sssd-kcm-2.9.0-4.el8 >  A    (8<xd63U]eg B೰d=K*i9GcqO5'( du&1&>T>>8ٌM->y s)hq13:>!q]CT *sQ^SKYM2fl@":r@#b['6> 2n%d%a_yo^;\Yf̖pk&J&C T9SƓ?]rs2[kU=gا_~7[I#](')L=$ǁۗw5фGcS+χ^<> G@{ j댩7띷`=zW^%Z}oV)mVj.5e2,Q$7.Ogjn#2v=jhv7Dr\/V 0/4c&ʰf;V0L۱{"hۤ >Ii쓚ҩ\+I)&Y451091e27a2f0ba15d3bffa11ea7516c242e5435105f498c1793e9fd3d6d114e4aff21907c3b509044e21f573f84519665055fde0302047c435bb500673065023100af316d6e1827466ffa24553abc666c492e566aa15c873bf8ef1e02caa6606644108ed0e47cb461a2a7c08a219f862b2802304c3362eb9d33fbea70d64fbacf838963d46471c2f104a5c0723ef5e8df5cea9df95bb17f6b9f7f53d4fb81cc0baa57c90302047c435bb5006630640230652f92f76f3962e7ea6843a255026e55f2ee9019d5effee777f3dba1c438237634b513ca550d7d54c6d2b28beb01e49f023022b294b1bda09a00fca43b18085b4ccd11962028749c048b25932a73efb32ecbfea81304479b2e14d051f2b38a24059a0302047c435bb5006630640230652f92f76f3962e7ea6843a255026e55f2ee9019d5effee777f3dba1c438237634b513ca550d7d54c6d2b28beb01e49f023022b294b1bda09a00fca43b18085b4ccd11962028749c048b25932a73efb32ecbfea81304479b2e14d051f2b38a24059a0302047c435bb500673065023030d7ed170a50e2e9cbcf5f0b3c71ce9f2f237a55fc9919df3d5876ac375f507a183e9ded9fac075a52d01bff87d65aae023100ab0f4056fc80d5303fabb68a8099e0da48bdc9c0cce82fe8fe87da84e62a4add33004e034fccad2fb2767a0d809f48200302047c435bb500683066023100b635095b722b7398e2985a58d73e853d52422afbc906352d3ae8ec41861294c7ff9049dad0f01cb237e85ea7b6cb41f0023100e05cd0225c4ce6f216ce97d371020af9cab14774df2c26896a7d207d744943b75156fcaae09718887095288638703ad10302047c435bb50066306402301da9c34bda8b9cf70439739c42006dec62a4f89ed373ccc254e5b9bd64cb22ee34c86749a439dd5eda1fa5e8dab037c50230550c50fd7110c14c3e41443c9919cdbb4badc9357f6dcc0dffba31d710dd77188ef116c7ecbec46a5d973cee03b5b4700302047c435bb5006730650231008c95e2f801a1b64164f82ed0b957d07737c6cd1f423f42855c48432434ea599c2da20d67f2b3cb448b0c0d5ad7ce1e18023063a5919375573cb12fb35c84c49b9e92e14fc806fa07183ccf1faf421dbf1a05a46be99d7ac93ba76dba9edba27852890302047c435bb500673065023100bd426c56f8214096ea6aeb2abdb3fabb614c88eb3213d53f1fb784791f57ec707af0043cc91fea5c550363c3006092a202304ee6be3cd15495255a38247abc716ec1fcd92d3df4b22bbb36a283366cd2249dea93569287363c90f9d8755ee42b30630302047c435bb50066306402306fcc0b50f5fbe2ba6b56c6167356042e4442ff5fd25d0c10f809b684a504a0205553ff9f7c733bff23e976c429c47ab302300deb8e44eff5f46969f25207df9886f402ee4075f52ef35c2138cc5739833a6d7e21857579323818583979185364267b0302047c435bb500673065023100c033a91341593f06cd3a1f21ea5200c313c7d57950cf0beb38d9a00267003d0d4d65c9a4276319f137bb16b2774919810230478394ff999f65d56a7a7f053767a7f9e1fef9935d773bd1423b3bfd7ae9d108ac2885fccda8e4069465b21dbb7b5d3a0302047c435bb5006630640230652f92f76f3962e7ea6843a255026e55f2ee9019d5effee777f3dba1c438237634b513ca550d7d54c6d2b28beb01e49f023022b294b1bda09a00fca43b18085b4ccd11962028749c048b25932a73efb32ecbfea81304479b2e14d051f2b38a24059a0302047c435bb500673065023100af316d6e1827466ffa24553abc666c492e566aa15c873bf8ef1e02caa6606644108ed0e47cb461a2a7c08a219f862b2802304c3362eb9d33fbea70d64fbacf838963d46471c2f104a5c0723ef5e8df5cea9df95bb17f6b9f7f53d4fb81cc0baa57c9d63U]Ɨګ*D1aG;%) (_hH̷ڙHex+RG 2-pl}4]&:%icAf>UX+a֊c /&Cy*DCn-]i)f)$^uDC m l>#n|Ŷi1zҚOݧn=,4v-ۊ Ot]uCNvsRCnq4>@L9ϰon^dQt^=]VkRBhA o YcWz0)'o`(qsCe*.gj*/ ,B}%[ t, }ZYhW9~2峷4Unfέd**C0N ͈>PBD?4d   B 9?F[l         H  |   $@ p<<#<(89T:gr>?@G H I X(Y4\X ] ^J b'dwe|flt u vw x y(/0Csssd-kcm2.9.04.el8An implementation of a Kerberos KCM serverAn implementation of a Kerberos KCM server. Use this package if you want to use the KCM: Kerberos credentials cache.dwx86-04.stream.rdu2.redhat.comCentOSCentOSGPLv3+builder@centos.orgApplications/Systemhttps://github.com/SSSD/sssdlinuxx86_64 if [ $1 -eq 1 ] ; then # Initial installation systemctl --no-reload preset sssd-kcm.socket &>/dev/null || : fi if [ $1 -eq 0 ] ; then # Package removal, not upgrade systemctl --no-reload disable --now sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.service &>/dev/null || : fi%vځA큤A큤dw_dwdwdw_dw_dwadwUdwTdwUdwUdw\dw\acfc8b31ea1b1931377b6c6c0f3541e0617be0a9e24769d5e1f32689120c0d6bbbac31b33f419589e342f20381138c0dea737fa71b0d67a0db97020b4451afd8c2f6ae53e988971d19b13a2104ead7d8f059bf8e7097a1a5d82ccb81764fd4794755c79eb09f8f29ae29ca24373de11fb52084648237db7d2d9389e2c7517b5a47e904fd7737f0db858b48892b01f2555addfa62f55ef07873c19a8c6e819c3879570a16f68ced85e49a8b5557e4b977c2200dc1255c71ab6f1b2bfc25350db59904d45927d5014b6f456a1cfae4b70456ac337a9b85e38cb7aa1ab3bfca6079fab7b5968dd8a76202cde32bb93d796ad62c64c7c44e3e78af459ff9c4777592acfc8b31ea1b1931377b6c6c0f3541e0617be0a9e24769d5e1f32689120c0d6b../../../../usr/libexec/sssd/sssd_kcmrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.9.0-4.el8.src.rpmconfig(sssd-kcm)sssd-kcmsssd-kcm(x86-64)  @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @/bin/sh/bin/sh/bin/shconfig(sssd-kcm)krb5-libslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.28)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.2.5)(64bit)libini_config.so.5()(64bit)libk5crypto.so.3()(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_iface.so()(64bit)libsss_sbus.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libsystemd.so.0(LIBSYSTEMD_209)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libunistring.so.2()(64bit)libuuid.so.1()(64bit)libuuid.so.1(UUID_1.0)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssd-commonsystemdsystemdsystemd2.9.0-4.el81.18.2-113.0.4-14.6.0-14.0-15.2-12.9.0-4.el84.14.3du@doMdbc&@cR@c|c_cc@bbγba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.9.0-4Alexey Tikhonov - 2.9.0-3Alexey Tikhonov - 2.9.0-1Alexey Tikhonov - 2.8.2-2Alexey Tikhonov - 2.8.2-1Alexey Tikhonov - 2.8.1-1Alexey Tikhonov - 2.7.3-5Alexey Tikhonov - 2.7.3-4Alexey Tikhonov - 2.7.3-3Alexey Tikhonov - 2.7.3-2Alexey Tikhonov - 2.7.3-1Alexey Tikhonov - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Related: rhbz#2190417 - Rebase Samba to the latest 4.18.x release Rebuild against rebased Samba libs- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2101489 - [sssd] Auth fails if client cannot speak to forest root domain (ldap_sasl_interactive_bind_s failed) - Resolves: rhbz#2143925 - kinit switches KCM away from the newly issued ticket - Resolves: rhbz#2151403 - AD user is not found on IPA client after upgrading to RHEL8.7 - Resolves: rhbz#2164805 - man page entry should make clear that a nested group needs a name - Resolves: rhbz#2170484 - Unable to lookup AD user from child domain (or "make filtering of the domains more configurable") - Resolves: rhbz#2180981 - sss allows extraneous @ characters prefixed to username #- Resolves: rhbz#2149091 - Update to sssd-2.7.3-4.el8_7.1.x86_64 resulted in "Request to sssd failed. Device or resource busy"- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2136701 - Lower the severity of the log message for SSSD so that it is not shown at the default debug level. - Resolves: rhbz#2139760 - [sssd] RHEL 8.8 Tier 0 Localization - Resolves: rhbz#2139865 - Analyzer: Optimize and remove duplicate messages in verbose list - Resolves: rhbz#2142795 - SSSD: `sssctl analyze` command shouldn't require 'root' privileged - Resolves: rhbz#2144491 - UPN check cannot be disabled explicitly but requires krb5_validate = false' as a work-around - Resolves: rhbz#2150357 - Smart Card auth does not work with p11_uri (with-smartcard-required)- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2144581 - [RFE] provide dbus method to find users by attr - Resolves: rhbz#2144579 - sssd timezone issues sudonotafter - Resolves: rhbz#2144519 - [RFE] SSSD does not support to change the user’s password when option ldap_pwd_policy equals to shadow in sssd.conf file - Resolves: rhbz#2127822 - Cannot SSH with AD user to ipa-client (`krb5_validate` and `pac_check` settings conflict) - Resolves: rhbz#2111393 - authenticating against external IdP services okta (native app) with OAuth client secret failed- Related: rhbz#2132051 - Rebase Samba to the the latest 4.17.x release Rebuild against Samba rebase.- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8 - Resolves: rhbz#2119726 - sssctl analyze --logdir option requires sssd to be configured - Resolves: rhbz#2120669 - Incorrect request ID tracking from responder to backend- Resolves: rhbz#2116488 - virsh command will hang after the host run several auto test cases - Resolves: rhbz#2116486 - [regression] sssctl analyze fails to parse PAM related sssd logs - Resolves: rhbz#2116487 - cache_req_data_set_hybrid_lookup: cache_req_data should never be NULL- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2063016 - [sssd] RHEL 8.7 Tier 0 Localization- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/sh/bin/sh/bin/sh rusvuk2.9.0-4.el82.9.0-4.el82.9.0-4.el8 kcm_default_ccache.build-idc28f0db13c979b61d4a0a94312f1f574fff538sssd-kcm.servicesssd-kcm.socketsssd_kcmsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcmkcm_default_ccache/etc/krb5.conf.d//usr/lib//usr/lib/.build-id/4c//usr/lib/systemd/system//usr/libexec/sssd//usr/share/man/man8//usr/share/man/ru/man8//usr/share/man/sv/man8//usr/share/man/uk/man8//usr/share//usr/share/sssd-kcm/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpioxz2x86_64-redhat-linux-gnuASCII textdirectoryELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 3.2.0, BuildID[sha1]=4cc28f0db13c979b61d4a0a94312f1f574fff538, strippedtroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)/R-R)R2RRRRRR+R R RR R RR/RRRRR1R'RRRR R,RRRRR R!R#R"RR$R(R%R&RR.R*RR0RR6utf-8d63c3dc0a421bd36c63749a3a63c3415228af78cef81fae5141d84ea115b92c1?7zXZ !#,?] b2u Q{LVjq@ӻre8z!* beh8 Xm*]m+S @u_roPRmyo}SP51V9<85܋E hIQ|ֹ`@kbZXStD: ɓ PW 6@y۱>}AsJ\~1y[Z/v*ܗ0|gV2yM} ㈪OL%; klx^]C RtrbT˦Hrl1$c Q9` :ut<]J% ]P&x-d;c|>YExQ]yg@ eD8Kj c`p/y2S/l3*{'WVuXm ۛaB-Y?.JY%K8d3<9jgR:k@vfԝYUvs-7Ksֿy<"Rd|LdZYND` 뉀/]A˞dW"d-nn}^۽_qr'nUҊR9u~:g, ˆ<1SZ(TvxR~xQk=)7[NRwZ CEL7w2]=X3Йt n| /-t!-6YhwGK"LhVA=kyw@"}_j1 %muKRjJ&Me;DINv!=h`%r&ő/%/ԭ|\=6|cGΎbf\Cm(F ܸ}<>%C s=2c9wGk *՗[rA6U IL }r31`:L[h_'x9&K̄晴KDž #+LpᚦWFN / YBUnӇ`h'ߥJjogK-ϊ'v@y=mva٘#{%OFu""բi?Յ¶ Pδ^p%a;|ōDIʓW("ۇKr%\Wyd~so5Y,RL^ٛwt^x4)&y _# i;v|F" `^iֺ &qxl#{] 2rA|HU iƪIE#nv#\8KTBom\Y>p~(rǓG=tk'А{D^+1Aɝd 扞Į!_F=DR-*o,FȷgR̽K/mwÞ@h/-{DdS;Ӗa\UtWީ#/7g١Т*Nݓs=gA7xwb,7w;ILJ#@RFl<y#<ȭd1iqɏ|/lkǖ?jv jͫƸ/'Y&0^}3b떾i95(l:M@21χ3J3 9 Zm4d| 6+ !w:!1LҎO?xSNgbLֈ+:G6͞O4rLO oawP=Uڡ |Yef9;'[_%`W[Q*Gu ɄGZ=jJ5Ӽ+vcS5FsqQgfǬbZ>ƽ7D[U5:' JEZ&{|‘Ψq-hɖL&$+J.Ҏ^hT6TBzί=TOfB"<=Hɐ0}*˩3s$ԅRT,M9<.`ihCʹZj'l!ޑg W0x^-Ϙzދ'x\6}#)SHk* D_"b!,<Ġv ܍q~a RH( E3̱ͭ 5r ;ě%n3u>srpxy@X$|tk -hz=I)S"IqCjG],X-Z楹*&# ,DsL"iM l؋"^d1= 7b/H:螳Q! ȔY<4^e#FZyf0SFR! *ƒKWZǏ&誉_mm/TBj0{:k<{㣐.^r2kcHedIC+W Z F%`1:)ytV#ݪ>[#-(0r 3g' S%R'JpFi73nZ-+v; ؕ'p$][EU\,ໟ-F'TG?cOZnj*H څq|SZ,!3kbc)l;HDOO2GG37,+'$0<}ƮfI}FM glkV &j 47ZGP k`+'КLH.H {GA+Ա"Xtz_#2g+;Ul]S wqE߿E.Gp`p=N.}(.>f @w]og'IpK!Dı y*fD{Ur|j0&pyuU'yeb6F?JlfVvIF. @s9SцGAgÉ~(Zfzy ]gbeqғ׀34u3rXWƅĪ¸-嵀qH._;gr[頠0W_yuJ.ј5UXj._ Y ս@{ah؉7?xZt(&er!6Aw-L 2Fqގ-vz,ne4Y P W+혈4%L[HL?Nixp2 P(Rդ&wn0kWnҙ},^%Q4CeͶPBF=ng άgOv$G4J\whئ+ B )a݀q&} xvx۝U5+jWٍblp(}Ÿu'RgdgdZ7*s">_.NCs0663f)9c(<&sFGKI/;sW v/kh&ʺ8M.PM=zhv$4`9`OKlcHk`(%b$DGA MXm\Y u@5m-~ MG32tM0NV9x.?{d Acp J;C;)2mٳX`0| m@l/]SSHg׋M'P^FD*0Y*Cy?SC٤tйNb`J9ߚ-zSiNh݋uګLjTX-n*j W@?"[s5)kX b8#/LAN (ؔzR*r*IiV( X\5PJjt` @"bᓀاnz 0xt[$i5@(~=ɖ8#+? :v'W7UbDfOYֹsOr H# 7QQb7Pf<0؛DĴ9G,=?˟-rߓQdNxr_t@*3C!ئm8'Ɲ$y Ts}/S6ٚO&^D+߮4jO"\d7nF@_ ĸqUKz8-KVN0]#!<ںZA .$](4beEDȾ GG ~˧ ^DrKX>VQ^N]4VL }:fw#MONE / gzsUA؀26**ljL4\¨*OZwT}gJj,%.Jr5 0c`W6|Ua;Vp .\fl_!qf|eC !ͥPvA3=e kbBVAuRQ 6 MLk T(ZO%(n *L.ܚ‰M|?IvSBH =bsehP,B< >bTbfm^<!4ۙ>ᘙ5ځm̃Yk=P)B/ 6KGIWiWiG(E)L90_E BbPWigpD \3R\D'鬵ڪ X9{0c-z3a}('nIm 4JU# o@@hƬh-)񜊍0%ۡs,XBFC*0?#<ʒ; Nl\ȏἠ5k|~C;I$V/ǐI`rڈchOՇ0ELP>H:^tt,tQA92`aLG]˛˛N\1+e n ;t7xɯ{{NnVdG},&,Bm PtpbPՇSML^Tt ëQPR茌4ħ6N7.}Ai({ֺ7_ qX|<@1gRYۃ*1/wNzz&!b ^ IP+F!7GMX|MZ?k{}dƿmST.A52# fP;uUԳQ$N#m$ !n&P_XG1kuaU pxVbg9TgHR#=f\1@s ۧe3o]GJGVI ,D!$1v|툑%+Pt.BKM9d|V 8q3:&p3 6m~` 0qPPGY'KVFMzüŽl%'%ۯD˜f8:ڗ+PvmyAaTv^rTH@ GJO<]IZ$&=!ff0w- U/8Ƿќ[ R{Vg @8j]})ILJ@usf*{'癞4߭&Mw|h >a9kٮ5]^4*;7{,!P(K;CyFl]yC޾#2pHw?ө@n~4]6KWG 4lv bcsZOnM ]GN8j\[%LhD˘>^qG {ͮvN2w-<0%RZ} ciE D?:$:~zA7l<ɝHPPue3ިE,ΤUlڵ9nmYuDS OH#HjfIyI'ɎJEߍ8^I;Q%g+ X Gf^Kpk!b.N̋f-KM:IMeYSCӟӾ%^nM %%t%șK25Pí_П+~ty>/FEdڍ}zTa@0W?ڃ\?KU=w OɝNj%7'D9k[8mΰH"C(xIOc[$ϒ" ]SXQm{>P OmLg*g i2"!,_!߭PrtrgIZ[pk< v Qoh)>2a7Zcsiy׶R :yVE]/=0T,taLF绰R -iwMQ9xɛi u5}\J -c7OkG,8'43E7q-QȘ» LHa] 33q]*pӣ-e+~w98cӲ/aNlZQ\ѬcI+=D+N}"!6,2{n*98AMūpe>Oao9oݾTi&. ]nk`9t +Ș@GCo ar+*ωOW/ضN9:v] U@RAr̽*lcP]G1~/NGHVN`(t4BcS9m\"6!^$c^y },v" sEeK{:&@ߗ |i^ X;4^uKgJ2)0`p<{E]t(c@`{/XJg+ݪo:͹̂-9 ,$Cռ7CWy؉x! j'K0N??.C葐ioo>AH&p#2D7I;KTԊ Qd,A !DjXxKY7/,X9ȴNsv16¶%C^+Ц r{-M2,<|wT:$isb)Ԏ~Zi\}>ECkԥ xs{'E롿u"&g<wh.MX뼴G҉gmE 7xuV}xE> j<2+ =9fYtˎDeƏ}#uCʜ `s -9L=k$ZP/ *%8̙ۣ~0LG DIKDpwaw`ܣsUn΄ETGF3ݬ$ ZI:T)"ilVJj+agqhXF-t>|s!)M*aƘMR^DQF䵦w( yͱ\ۥֺV#e2hNP**na{?sE=հPuXLa 7+"s0!ϰFѯKOFwzC.QS9$zC ҅-;5jH>U @:줏; 4P1S$xCXTMK>tطQ娪 x#0ʱ+DЉ@\Man7{iı&O,4wωQa/d046F͛GjI3[khs7HhTW^rIfܥݦ.zT[,FuIHb"d-a.LOs$NO!DKGӈaE6%Pkޛ(9k=Fˊ͉7v?(/ZMhOwʉx@X{rFJӪSGcv],AFEn24 ^V6D 9j{V4tzDr)t$wl(I7r7M ʥׇXoMپDe} MtwAͷtv av`zU%bO#i<>"΄"!(lzj\1 *Ql ߰)4AȭB}da d%HφONMY"Rӊ_ubR f(Y;!=Bo 1eƝ &_Ǚ*]xB΁IhNwڥ!GI{> U4j7&dIs؛V< S+i~fVdݡK9J-sF1-C L7%ϛ2tЮTa:ij,vKPtpaSq8 9m=wnbsR7 g( GA Ifodלh7'1O]T `8UFM⎚En{:̣,BV @(͛l굳EE莾Tn`0g$(4gg0&f o#|:trυ]e#X>ULW鉳Ep!fR`g[3ܦ.D݋KyyoA%1mea7:%B(0Qq GW VDt~\M(D]&Xgmq^1k@aDwv#lyY)e 6eTUa yrK`.ig;M D&YMdTϥ}wtRm's/M٤YxmF(vpS#+wxH~1q:}`" i{n?lcW|?^pfFB7ra2@ZKi3x37(E| :%xo vU)H=H[p>a C>mL@*LKt2eu6)R(x:q_$dpʖ-sLl!F~iի6Y q}TEڹE~deG H:^w$OG7bHـy3BUfp3SG']τIfނg{w;(k%K]p * Ԟcѽا2K[õ.rKI ?geWm73= Z rj<F@ u.ӄqqֈr#(&)$I7KU3WbN(/sSؿf֝9燋w[K-e .l߈;;PȬ:ܘ2> 3IX$)^v5ɫ4ytB;1v8.k-CvЃfdz\_Sӣxw)̭=RȜ.~N2T/klDet7ma<ؤ:橴f01;Z1 ;g*˦q.L]7?_VQFmbkd)) ѩ6xk yuZAZ JΛάjIxD6РZo [})Q=?\/e_]8 Dzֻ&TT W66?jPB(vZ~׺[#p{IhdFEkW&]~f+OY$BͨTxw!QQ _穴ه^J:F?zj~JH#~Ķ]Fc;UG^:\n[njʖOڜE?N JR bƷk$*% ̏իKm+}!Wݡ'C;b1u޲>4[<Q.ca趷=+(3Jm!D'fU9$+wԐ/ #6Zw'H)āL'53JZcGVh-|M9Mw..jFefx:[$O`-wgz /%@h</%PeZX}GۄaCՐm,sߥ̀`~Ψ9t/Ics4ލ. o俩P[UƱa 1cė![0)ȏFp[f:9wu~!-+I&Pdn!״n&YF|1or 4$oШnxXoBES.w{#W>}m^vkDi?Ϻ>LJhVg P|=k2yw |I!~4uy% F>9&|4pCouM͢64K ϡ\o'ӭAAȀSV>n~̈́VSP?/{TF +ށϖ'6?tr)$pK;|,d $ȗ٢IXK2;?иJEDM!e053d5f;>]Cq<[ .%eY}/K-S>;fMK e^^|RMO8. o 8!\xRn1_8R퓐! x^Qk<4A%lA U}hQAqoFO7BkV< iRE6uS)ޠ";b5)zcj7sQ+wTPp꫃궐*}9JDš+R1zU^oGZdz.~*~[BJ e>y4j}y[[9 2~VB ߞ-w7WΏXϛ*Gd{W9wQ3Yބ.= ^ڼP3Bћ$o D,`=MJp,+N7Z G]o "ݒc?_Oa-2Gam:ΩeTB3ZU69ҫ*~c1z42g4e|_zx:tbkKJm?y \ai[.șD/Ԍ渹oX% ?K樉s ǘd{Jږ]0] 6T,s8OTvV]/Tø;! +?,e \0@8mmoj.&o|>mOTǫ$qjw7jSVn4VK\KFH"nbd?ك&G#:wn#X]^@ұΛ$ 8ZtO?<,=N)s<= \ %~ Eo;I0>pgZhK'ʽ7i9\=Q{~埁K5"Ee;U#h|QGpq*Yo|Cͭ4W6 ᑖfw>uWjwY47'p >ss,1G(e?^1]8>uPZѷbm=Zߒ>Tt R/2S|1#KWsfBaq$v< Ehʒ 8T^"uSZ L|7]^`hK|wIvJZ+y.YrrR{wiT:UF?63$ϺlWY#4=KNp|psҟ"YxO"nQsQySε*x8,}Y7>ň4(YPb?ZjDZ8&1d?z|T^dژO \P\O$2cI{, r0xGŗ2lkh[C2k;@ߥEIXOM׭eDpT + "qQc)7wn 12=؁4]Jo> ?qQsFHje5#+ぺIaG[#Vy) aۨhk'lSoU=)4h*{;J2n7hK&9_jgLey'!Ƨ WBMAcM S~Ĕ.8S6qoq6L,:2?U^d},xީgǒUhA|uD-} =4Vcd 7g OƂ:t8@ տƚE Tzyn+T-E^/&2 OC9C i:eS.rŵ!8[S1''NpZյ?~ZPeClQ%/0!܏>A])A%]t5t@ikv0(D*ܿcݦas`/۴Vx%e9ws?z~Gi HLd ]:a!z<` wL=/{jkMEߕi?]5=Q}:L,|ׄ2Rl8_yT[145 a9 ڍ:AQ}3M7TH=זbG)!*`Tv( 33pwҿk u! 7ogc6WoOQ4qpPKyVdٳW8/S-I[Z%43H)EN!}y+h;R9\⻳[A->+cS\Xu+=L(|w-{lbn3}A (Z &#R5R q8j&?3R N_3K-lVͽ#9nw[;8C1W8 '+iK,"9&qCE;$t 㸀dVZ WL} x[֊i{1qLON3祿~(N!*01aCc@OhvO/xp&4QqJWg"J1EoVe-VW'V-OWNQ*ΕX->x6ʲZP|d#` rЖ?MG<#>u 'QXsQ>#vٚK ƢTa <*m%`jxysVT2^Ƀe|*4|z81TV2y6I;"JݑĀ*wb[6ML}fo)= SO |@@04ũ0K*i_m(״y/: V,hO1yAX7|9Mi 3vԕE@ѾO%CHndz l<2~Gi?@Wԇ=.{4zZޞM1j[ OXQ+4|2͹br#Gſ:zkN ev62s $hXXSg]~8>GIJMP &8#NNxK,SR$Y]4EIJGZ.X"_юk\2ϜҢ G˳\CӘC)"sd@#_ ű b2BwYp>J.85RaER&SHN!ӀYae8Gt[S@ 2k_M::V15emTX/JѥpNr^Bp;'!z7#kŋU1#] VЀ.xw'ZtoL i  Sa&ڞ#l5QgqΓTۅ؃/C Ux;h{-#l,fsW ]ak׵,̌?B qPJ Xf.3H MQy&g"5L1V;[jg =`0tgLz,Npl]TA–wt7hQD<9hf~#([y:BuIE=ʥ!\%8E#BͨgJ>.-t-'@A^fF~H.8Lj;ɒ]V2NflajYJf&젳Բ}pℯ #>̉?|iLЁbcL?<="n͑椱qjf/|'{0ߤEHFY]|߰/$+8. r]45^hh}PĎ%$~E^$mYu 7ouoӡ 2@XJaƃ_* аM٭d`]*gqKajXi5ccH<y" tƹL޷y$|tL(%JNvDn|nrWT202гoR;(x*iS#ٹ)XaڔHŵ[%k(ӅмlgYd"ae>|T/ 5I .lߧC%^Fp= X[PCB?,(mq>5pVCհrMӱμ*هE_#]0*M$bvcF{A›"xsB,BPSkt6:!,.tg"G5 4+kLgmf!zژ9kMʸ[wtsk\b`%.S=ލO!ʋw%=y =cOMAԟ`c"&4  PYLSZў ['}QpnEZA2s+}!%P HL~? t'B=-9jM'Rd@#%&= T䉄넶>Zݡ * =У57vJYT<~o{xJ[NW۹9~TGᄇ <۳4@&!C &Y@JkzZEj +`ȫd ݕ+)yT].'1*nnJ)\VÄ-4SID56~ :m;̲hWwNs|6~,1|P.^*xn'{Iͦfc܇@+mO,rcs fBÀI2XL+߫U$NBEgQА#h1ِi?ý_ hw ]?Ao&S$V8HGho*NRXBYNCx$Sc"4th%IPә.mv?َ Y:ҡRD^q5>a ww77[rk4`# XO{s^d'2Cr)brh F&% |{"8)翻4X?GPKNLJu}IjlƱ%B4PYK0'ZI+Ce2uc@gc:Kzwfqf%ǒ8dmb{ڤ@V6[|3ֹE}sHJ+_8Km3ueURp>‹P}@yXׇGQ/(RoP/^C*%: ֝9 Ʈu%5Ij&(JɢAduAP7h'Ԏ}ك[{PĠ[" bGDQAxg?y 'CA?c\6eB9 ch~4%F@Gg7 3=ݠ64b`[+L䄦q{,k'*}( &Jk{HBH)]P:ԦllaJ}zͽL6K30WO À9yq۔Wwy-)k{JR\Q0D=N%uBf *4gr.Xvt"]cI!z+"kY2}\kG q*!7M4xvu=fEWNx|Hѓkq5\QwN o4\f<q ^6(nf2׆aw㸽1?}P= 2LApygL |ٽ1Qs3〖7^6-74, 3V uDxjP*NTܩ B2ׅ>I^]"-Rhb!9hkTb'&E kxE{l J ӜJ/-|%y)H1h^x&Bc7(AFè'yRvBo¥wal$vN/9See'y<`mH%9 J^AO12fM/+γWT$~1[aY/lZr{d?BSEd.O(#{3zdw^%@Lzr^Q(Ku-H:?7Rި9LLS  p-Hm ggp 䕙j7"SxEF+(l\«1bd'Q#ΎO h; P ngc{~ :J?|=+9}nÌ&Ҕ9%r)kI>ۍ<5mo8 [S#ֺ@OٵY$j'6FTT_0.GKtؼI7;EjVPM15҂R`k92Cvf{Ol'~Jkk ٲVl3w5)fL39hZ6ܗQu4 (jíUGM |epkY T8z%feVQIE"I+w-l ]3oq|WL ;; 1?B^7@o3~0ET{PMa}' xT%h7rzA\iR[77(CH3JEl(>bgO[kiM9q >&d+.lpרfmqhw67x&B@y&)<Y5?!Ob3N ~TPt}D +~f2_),ڝ E@#f&ӒjUJhv6\F5Kɯ"9F}ܐe䀬1{0~t.pqwdTIx/$=׷]mr! RRNNN825Q;j?ap%p:&{l6ƕ$ۑX[jzש; e#43Q2v8U5*/L[䁋f{L/mЯRH~s3F\;Xmf= ˥ n!pGL]z'^ 캅if+FϓA+t>L*I׶ έеK Ii Uz ~ĝIy нΌ b4+A+ s_[ߋr:uB)]0i/MQC+9:YvXk,.-\%md;ͳQ`3 Mr1RD$3װC  gVQW=+xr*ȮZI {Ap9Yd3^1]alt3x?uf\/:QME;d\ hG@'nFԐKҡ`ΰ\#h>KǨ*9,T$:mbrypI0 AH[5{dC@ţ8ڜ9;6sR3?$̈5aVCCi1^8sゔ 8<=~٭5v / T bs lG^UZH+o` ,Xet |+U7C*Xeflj12v {I-jL7!Fƪ6WE@{,*t+ =yQb=[oR=Y`KzVk$f} n Tg) ,ʸ`aAHA$j3vIpeix!!@"1e`3n Yb l-vrI46xg D*&(}˄Ȃ%o=ٶ8 p4cOh#lZh`*I>tP@Y;$?Jf%Y-eGB֙:Nf5X(s Hף&'dLԓbL:pX)B3|Ά{!XMP۵o{.?>@Hŵt-9 LK]{P$g^)RW0jKۃQǀ 1|=vt'!/Iq0J7Ddgh7v3&00Co dAW9Hz"%HX+㙿p\7 Lw3@g9hŽ3Թ֒}y+67N:#Ȋt_ P8X(׾%FPߟQY >6[ۣ}L0/晠VO9Hkw?W۞Q`̜a}G LuEe.kx4rD4r=Ƀ/h>]SRmby,$"t4gh<DkOpcXu0q^>sNu(}lNb٬fu~B)Ns0˵ZOQ~cQk CbIhF0et99kt@ Br(h>T=cxB$WnaZM$>4̓ aZ%[zq|O"WyD[ 04B_xc>1L Ws};_J5W<hb`A3"'K06$0٬, .%< gRn'*%y,밄| )`oa.+1"UiyB>=w}磗\mTE*%5TgڸbFΪ Q m P_w&:Mcdjp oKV&WWIR}u61JUގ&!T нe:._R֯2eH Md5U5Ɇ,Rm53BK؟24;(4BDi(:X*RuuUYfA>K峟7 '[3¶͓] ǹ3C'O^ѿhR>S U܆y 5GRY5,'E/+iI$85L,/J+shV,T!~`SC&b̴(8b0Fie{bC?K QUm/ѿ&F4dK$zNsK J=9u㐈Qį-^tLboY?0o0 4}7Hz)e3 wY[\色kcӹw4zL;)7}-utiu!-Zw.ڇ:=0$JoZ0̹Sőa(G' +lDæs&Dq)Я%&xؗh wͩQ +m"(W2wS+bufٝq]~ \Y}'SVD`Rokԥ>;26ӆo(tjonRۄL6 -5y"[.j UuhU8g1+b95yE"MTDvWa4 (߄#|cdb8Ө /5.89E&st ;8ݗ(C:2^Q=Pԙ{VH'JUpM-`Se 7YEQG2-P,k0Y׈qA7A׆>chygYPJZy-&L %"䖴X \OB%RCP.[;]\qƍgL*_lh\ֳG&NoLJ<^Ĕej.ekPXĞ:ߟ6 kJKY^hKT=:Lot+_&i$fn~'$myi->kH/C}]xZ!`ta=kc/',м>tPj1uaY[khPpkʅDgXQ$=K7b=K>ffhu/N* e&nY4P06qX퐐AY1e*#w|ph6%E6RE(AӾD6Bq`e|c fu Ixp "^R(vcxEsYx+BK0:Azg8doQ/OpH:mgem.7eN!MHhd^lAgQLpԱM #~]P?y`&UԦuAI."`iJNokC[+Y@NGD;.Ǣ" eS&Xˡ)7ᄙpƃTRjx}L` JdB̤do4U+LO4ghS+cbYVt |rgr{p7xRS(-yi㪆@$J`骖tr̮=MD{{OSڳ*&ɧ2M/* %{.|WWN.0183cOsd?Ogz4_~qnHS$M]`3e'&ngl C0nxQ^~߰iԟw#Sq!eL8T8EW1NSe}bD7eDB<ǚX- *L̰rn'2, @*6w2tzH#]UϬ%U(҇[WS*X3!?z4D]燞1m(@+f)|N\p~I,J[}yգ M0h]n;;crԙy=TIՐfZiYl0U_E ~;b_Hk|M#3acJ̄\8dp":n6#<k Ujvg+G k8 W?wn:ۄ23Dj:H(Y f9ll˅hLu)$ץǜ,vohP^1ue/=j]x5|XwvaXO+){!ɗ?3!ai^ Zg$brH{#Y=5p?Z鮟f+m9Ay;)AR:4cQ`u&Yxfq^|?1zۥs;3@Q)w…~ KubG*J+ ۿĎ_Ƀ* H{Yӱ#mMޜN/Q}ƽ.n2Y0 qQ Nl1~{#TY۟C[4GzOMUé$W*am#۝;-`qWbz@7 _g>NDAPŒģflF3n' @јV|F ~Ro}j+@R4Ջu'6fWQgJLjUwȟ"G`- 鴷ia8Kbn04flb TUa3| تj2A `nhqS2j¬'ƴ$'UC6@r~ٗ_إܾ[#eV#`+8onv@96whTi-=$墵B|:fUj[M vV\AjiֻPV+d?o qJT; }tz?vte7Dv [mjoNy}^P2#qKϿѺbNDb n5Dz+{>@PUR6g=MX}gs" \֯lXODļ9f)=Ane5_kJpN(2 Ze)7Ϥ2x*P]tJ'?ڋC'M~~y4` 6|+_mhx'BὩXuȤ}lbZ ~% 9C"pPMp C{~^l w*tPOgG[]&>pq75~I7KkB.Wh&[Z@vTu=_$A&>Q֧>}f7]+9ڭHzSLƶjqڂZ6p>? Rd=Pb,)&G62nu $TS)Aat('qj7 1þȮ.XyQ81vMT:Ld`ICe0 Aq~#4Q0k^"~"ݼKc@;3 zJO{ۡHZy@ ܠ/8jh2R=xQ.@ tfaUsc9ޤSia?/,AtH'E𚸱oxP[tnF|\0~:|2JC%}ikH#c"LY/\vt% O-Hevb^MP8NOok0penROwyg* Aw+cs J58{㗻ò줕A8F3KFh:DfSH.OV'ذx$K,/BѦ.[{ڣҴD;1zL{[(hnRNX FʸN෌ZcLWx"JD,ue=琿Ԫُa1@;)bެ^^-Qz]*ǜ8%zM*> +xP.Vhݗb )wlL\S_D10FkGG8mPBaٗfriYJ3l$U城weuS:M=S=S0 ;5꘷2MnCsf-8<$9G^snoVOa3IhwW{m(Xs?HTMXd0f K;3 S4^ "#Y-#(dkLJV>G_ksk02dy7pUŶaְܼb}9ܪrIjz:! pĖ7)nߩQV>na zcƺˢJh*GFE%f *2`h-ܸk溋@NyJ'˒yE}D)?BҔauXiR7[c΁T G.`ߋ| h^1 g1d7?S0oLs|WXP}S;]D}9$f e GCs2B|`IBX0e S~.ɘ?8S$vYHvUZXxtħ7wLټGdrfG9dlo@-gK0{t79n2Rj$^^V#%[-=j.Isl;Oœ^Ab~1x6;r%Y}L D0CpGXi/+Jz;Xf^$=c xPmIͤ@ιx< gPrgLvb;"uy{ Lrk@nm[AWƙ1)ԯ\n_`n٭ah2NDhQ Yo .ǟGv'h,tܘ~ WdoĨYoB3ѮVV a-LX`IpL8#Z9uJxL'ֵR#Ի{3')k <6KwJp% @bwKNƻѴVcMt:@?p"琢Sfe) ')`$3G$e /#U}J^#IO/q_ӥ8uE7kju ne96NrIF/$/1bJNxw_~~Pnڟ%|Er(L̋Tb-I|>5aμ\ńx9i~9\l(8O]+'Z)/% nOK񊛴}Op; ux1]O8NqC3rS4|]& jDEhvY"&'Z_jrbQuuy >%5Mqw66U)HLu\]Xl)\ATմYOWx5ƻfH6dҷMWd*)AćP9hդ@]Jr6ڂogLE0km}Pk>x{wR2¼e,a*&.^Z [3"')D8)ꌥx:#7 ,aVhY]U>·z~Ep5ٯR,w$DIH>yX%LV` P. M`^6,o.rwU E Y@K,,ߛ}Jt֚`#W4B:D0$,MRϝȢ]wLzL)p) q% ds^o5hu_lஞz7@_}X;$$-`5+*JpkQO,\9 W𷰠%]VJ!*ņ$cؔd;YG@zePKQM8הur y>ZR{*P_+Q0d$t1ПLa9e ra-M68 ~'mnH@H3hݍ~,R^qEI_SB`LHF&;¾V0w4м&dzD[O YȻZ5q ƴZ۸,^tߐ7jyʂYv7eBA .Se=e(c=!D/PyI}G1=ФX ̇qع6=IM࡬`N-|-W k'2lraxck;΀,lxmT^,n!TWY/ZrNǙɕ2mh ^ &4 =`UDIϤ|5Vʀ, ,I%ag:e2`Tf(|oܨ `dj8Qry1|Wݰ7iJaT0_F]4D;Sm6̸c|&ME/ ?QA*;EC-tSF>9~9VDB2 l!m- ]6}g+0J·dT|N:b6sV75 :TsݰiWPP})U+3+Áv0Л}1 EO#Kr,$,`I&Xu{QZ&Y/S3$gܛdDx;wv.A5$߰^fg-ӭ[Ơhw(ق⍁t›&Zy@5$%eUfƀFpT僒 ύi2Hg D0vfW?k*UX_Uət&R? hc{Krxԝ.\ 8tȳtڛ"=T:w ٱ1"X#w7@fLǺ ܠ` d.bH/ lגp6R\A*LZ=Pe}ma2&S1a.";{Gvޟ[Kgb#>*jHQht"HlT?MaAUhfFbt1|^K:HXmnih~t ŏ`gx|Sq)aؤ{-V7ax14L<6y\m&En!'V&"z{IT P\*[M"IjaS;3>[6L-/ ߦJ ^HZ2 =!°ᄬ&'6  ck!dzb[ rqnɤw,o$ne#uO_y䌵mC 5p6x#%᱗?*ex,L4*ZSWDm66#-ZLX}@ zJ{,GL>uDbw~!:p&x`1\ x#fx8ƑVeC3PJC6EixbEizE"sypG|]G'a<\ZmuƲ*(u5`?Ć$?[AWw~R7q~Q9Ƹٙ8[pۈKD2Ì%JNU^=Ih}wy&u$?[k%ZA}~wTuu7dȠ;Q #8Qll]K\%U֔ z##6fY]b Wy}᠝PLw$he27[mki @pzlZnM B@U7[G;P4 <>-1ıQ|/+ :$0`=ؙGU.0VS/5Oo)d<>ʈub7Z^C:dr܄jz'22I& 'I;湕o(1?|g &mYOn1=pՓى{,^18$(/ cVa5A-$[w4 S7׏gs\h@_KYЛNϑ%=Ywq\ґ"5b//}f}w(Fʡf"j>j^ r/FH! 2y݆٪MR qA=Ґ7))EPz`j F|-'Y8"G)4ւL`D.DD&|.?l3I_O| E\@/Ʋž1A.MBQPH2ue=9˘ڒqczW\ ʷY7I !5-/M;[ -s1 SU l2tAm 3q30\3b$!d2_! Pv 4v JvOkE7|ZW-ڕE`KO s~Yt pլţ]ٱ\]NMccF ktKg^ߛX33R#u\.ja Cn-ɚ5ٸ\Jw`cJ'86]ՃdczchdMu0 lW&mlp; ׃hR)^ XM~x{z'ئS.S\[8w?^ g&]J9`?RCr:#/nFSr/ VZ, r{,X,>40ԓH{ؽq޼3K!N[o:Q+dN+6S<3SYЀC'E;9Z+vVdӠިK,R pWWX0|7 15lC!uyUf*6w:_G)Sر+hyHhx/%[,EcuyT 5>~)W?qרvдh<5v$qcʶfv8N} =Q-!>ܕ!O59;w+BPpf* bٲֿ'': 3ЬVN]caɊ+ԍNvbvCkba2ɔUB\0+̟RN/JE㿹I߹8֨v7geSk[:zXLO}zB ,pR!(/"V@@8H[YkúzK|/rt,N꭛VX` &JVP5wDqrB-2>q{ vcE:LJˤ8|)-`0F2=>.7qY7ңғ0*c mlm2U)FϣZ,oW5Ҵ j|#6} *Zg+ƾQጓ[mOSNʯC`JC|{4],l9w&"xԮRy;-k5Eu맲ndLF k%)qީ`Kw,ajDӒP2Y8ˡPjFK, +D5v4ޘ֗ { hao֎q9]V 90dG%偶N+䥛<,\qn[63}ϛp)fk8ٌP/"7a9z[jYi$=RZRa2xᥜ27ذ ?0kV6H2]hZ-K6W⢞ڶ_\.h-|JmL_>yj5Zh}C]J)Tl:<8D=s7XЂ ̦-6e~d, b931Af=Y7sdȟ1c8 戆͝n}B)aD'yAq[#/b'呹F4rq)cnq5oQ+LwZP1?NPnir.#zb+h 4n@GSL08ߘ&c׈3oU׳nYtwd[J &ŋ;IzcNƫU!Ex?† NȆ] * (F$eAR2sNb[sN-oFA[5:Bv @IQo uKUkƔn=(?=+G)F!"iҕ!n?eP64i+&nT} à}y@dBR=vEw ܋E\[Af4OewK8$f&!MgRZb|C6k v-39nWg,'`ޤUHXxDř77•b=,mhBtIbE?L Fgh7-rݮ!\}D Sd&/yԖ6 iC)얔$T% ZRRag|cl!KM %ﺭwi:N>ud6F4S1:y[lj\#ȝ"?f+-\`%].Yyї眍Ge5lh#S^dU씙ډ3nN%yPu<+r>">2\pfp!%&.aM hM *r?yZ֮S*X)r<jcoްB~atKHJ\c*)D·ʀpr7o:" \_Z&;Meұ ' Š=۵H}]CٛxkpdO6GxVc/|2sQ $&}k~OG>gj-׌YeUƉii^YI蠣߀'|KzuAWLv p@ow?| >g+)D9^Z~RPޢMH~^>62@Lruef6hnf%k;s~FŪ =s[떜#rg(X=y}VX"LiՍobd(ɟp,JRm]$i568{tQMy3DߪL=85{1㑇RRr(esY>^^]7ܳnR*&苻vLGOtt aXUѹ"*/kXx7ޕ/WWea4qu6K+z鶄Br~u1dcΒ(hj=XuF 1? o?ggo"c깃LJb((q-CX.lb;0-|GR~F@$ca\!;-Q8.U Q2|2R= Ѓ1ŀncRߤ[7=ٻi)hHIMdaXqYkcN;?ҟ7dy'>TzѲ k!I!r.Ͱ/۲g;7\[H ۔s@X(p%yبّM{^œMxY\;  Z=GvH;D0m4vrn'!9x ڗ ?;}MQs"3"LHƵߊK k/8n |xHz/^*McVxU/rOKMveHk_D3Ś[ 0!GNs S/Wŝϑ.@zcաW(|ϘVZ)>iek$Sj v/׭MڇK?R֪@ak?'eRH܃A/^}\h4JR4WTk#~V&VzEdD^۷.?:t޲sr~' 'apQu-N ,w#xMvSTC3OQ)o| Ha&HrаULv>.;A,pϰV(MO7[@9']I Ai z/].Mj-*]!,`C,s(BcЗ͔ś%ќ7nX҃'bxk]v[GmCMh,R! 3KĦ'zT l1=s;Roq sxzf2t \/뛾S~='qOYo,T[ϞeY}98; -sew* Kov .5HFֿҕ=sS:]"@D7ؕFaydoHnrD巜pR68IA" deD3]ȫ:zbbLj|hLG>/Z48Z[%%Ꮽkҿ'B+3\NU/.Xn!^PҞd@s |l*ZU#1 0SɞT?6pko . Mߵ[X}HV.?`,6BTc<~#x3RX11 r݌jn@AS}I|dzU$5QK*͐$ň}l>fD4R\Hxa'jȲ!g ky-ZCQ'F[Jfc vM)t#((#ά*ƠݏWvh%޵%{ϓΚs~t%.1g:S sWbaQbt8sK j=)6Ƌ;ߢ!J>KmN_ߺ ğќ#ˢ:( a ~p-oѫuTATbW9/RVh)G Rij8gE>Ĉ\kO1B;yqj2h/;n :7~뭘W6rt7ivX` TAcPzFM'yI Uŕz9xRyX"}ޏ}TtSfI![-q}Ų7Mg@GN|==Ǭ6tlL+ߗJj«}{k#V}+N-ac vYXg5vWޝ7S|,~=ǐ myYu$"cvܹTȊ݃:Ϩ PhǾm4P!ʶSq_9ZD$#٥DFTYCV62@W0d$Tu< UGh!52]#e>N!I/7j>\(mYk,I傿٘WI!gXڠ?^ha.3-ɏ^K[`Q?x wx /u=x,`T9zw<_xpU:`kV67I|p¾+*1:ak9%YpL>qJòPcEV';Wa%'UʻP \ 6+h9Ґl (~@,u/AAX{ 4 o\iyc6kRQf@-L3,3㋇ZC$ˌ@5Uv\7CyovQl:fΚlȹ m}!Cez>p/4Bi'd8nɽZ,֜R(?ޝAW E>UvP0eu}Y'Ɛ~1^أ0^ mAHu:NM0٫w,%aߺkΣsFd)9P^[XU4WO(y;+iSpRGs1+PF3=#vȬjq) uC3##J V #`Ec֕PtՑʤ}n.aLS=,SC`~B ^U/0:}PVʭW}[ypQaPVL~j燙3:cQ>>ɿ2Ysl ! { lCx^'4Br?5w 8[;,u]!Z`Ms0D Sd`R. L}Ej$ݰz`I58"Xvђ8O XJjB;%,}O'H2SXS&d(pЅ(*h.0} ? "09>qbVf&KK0/UXETA#^0nVW|`fPmʨ#\k?+C/$2j$9}3Ƙ/ki:ev8V4fqyVj"_zlݢH: ɒYlX!f;@Y 1 eF< =.P^,Vy! ~8xh~=iP۵3[ [>7R|`u];fym PBG_-Xwj7]Q(XЪX)llrzA*G^qS:g K0c8-g3UAzN(462ѓ/!9Y U>@z2m5Y+>9VԉEtj T5+Dw.&9%+NMg ~F$8P )Vo*M4Ý*-;X[ ]AWѵ,þ\gځ<;-@.wJk~uKSwdmsٹZg|ԝ-IMk"6f[)kpExٌ NTYP >l|^Q+όpO֒+3/q>7]w.h]pu GcPq*lA'HJ°\@ md"pWZvLbm\ZH-_jY-"~ի+A DM XS$}0f:nvs3ȇXvk'G]-ĂV%nmVS)Y c.O'Qi>tB" BzǨ|L "h1SNUF \5}l#Q >tLӼ"-S_/ߋeLe=u ggߊD/WP]1a :@5b 2^j3xR`bhbDh?SEj[JLkGG릘oۃ{`+Mk՘ N:9v+f;MWro/itS6S_ hkn+&Kxŧ@2MI`500 jޮ ҶP%-`k=ZF W#d!҉ OUߣpsGّȣ} sLH xM&|Ȓb)[ͥN % ?}9,ع6#b|lɉKH#B1;뙫Q/J*̯h*m(#?~h]3T-l-=xPa@q"JܩӟwaO^S[Z>;0ܮB18/.?86M])k~ DBx4$,"wylͽ 3p2Jqx]/? I`'!RDr^EԆ5_40D&G/>M؁^UYPߧ^[r:Ql@%h> 9jjh<c{%v"I'ȣSˆzs\vmm` V~"3VޕZ5CEF CZ lr8w;,L3fрAp7Gf>)Bx6G\]C\1j7懔Z1El &%`A- uq)ZObwu@DC yW_UN\zſzn:sOD&dIKAr6ufY#tEP3M%V)&9E+w2 T3|Np -݂v% 婸j ifpI6Ž fr6=-F +6\gQd[9GSk?0$&BRgƭ|hpI>V0 rS/&ziSX{eT WK5UVo17̧QtN}ך+KQtR C,SUs P!*>qeA"1RY%hB0Exĩ'uI9RNۦsW~wdUP19KWnɠ(CzuhFA:{sQWLfJ &=Vͦm)k^\rK&޵U@z2O.\3B=0f L5Vˎ.{uIqxAdy;Y%` ^N&Wr+9,U/vpKB-;Ws7V+16`˪Fʁ+Qp%_:/܌X꥔LȺ@̦VTl,zNKy7[[rJB7ťy;-;eX$@K2@>Uͼ0htכ xP)5=w' !g6(!nj#v̈́#~衝xU):ēj*1EoQČ1&uʅ-mԊ7: -M}J62R7v\gkp${^ȁn#+N뛔h\ ; ]ޑA@Ov;d %!Qb+4ƞ^y٢"Q،󉷌ΪV><~D)SŹ4Ap_`ƺ EIf+/W]7|p8O-@Hǖ._ *-"M؃E֦' d'IAqM'KXqv} md察*#*UPJ {E]zoO,lwh_۔12`d$fF.-":kq0SGOQC!(GqM.WӡEx7AJPe|<Ƚ )v/1w&QP${!iCK @&Ɇs^8Q%4e"uԜ hcM:-1Y1Ьޕ&,ikV<@@f? !*EJߍkUc|tAXW7q#u[h oY&L ʢ5ἱ2>KV3KU5$O䜼`ᷦn ]]Aά>M{t*V7+ݩw8lu4~??Bp3N[Y_:hM{\(7h*IW}hv:Ar)4LovE_I5 u&&n`ᡉdډ0#X6IhG\C#kbj׼uNI)`b"xDgڅ漼;6YgP=Y?$ ^=;{%m%l~Tͽ!f\e `>m%:xc})m{L`,,EDx;%dvn0cBЃlң+qm9ج{lث1.QT\󳞜`3<'PՋ-E Q%~G3ZPiEZ坹(r%ʤ - rlDh"/+PFB4}K%t<nmC!f>?QcH-S6I7` ?@5_w.j ˏt[ldW l%l1hJ:!,ÙxR66,BN#?r*q EgSuU<&lKZ`KEA~n'VMxl~Z~u@pCgqRV 2U_zwH,BTea4NMw"RmE7CTG%-lRCшd& j㻞"#~O-177+>BTq+LERwvW 1Gړ{|YJ*pAq(AbpܖEQsGf b~)d_8aĐJQ|9J%_=cDfS0`a4w*}uN삡4>^v'(uiY&88aZ<~w[DNFeWjkp7{i$9/%#Y=q!B9Pa?skϸC\~W &v|Axp>~3YuwUFfU| );|A#ςRMKnZ-bg) *%T3ݎ/v~|h2g >U$'1ɮEu-GqP. >[S%1o{@ .C/LھwJ(`{dٛ\ǙFrΧ*avrd"[CkxI31!]H=g!lp2 !a"Fm= V[?kH!VC4+4̠CӌD/$ 4=yDZNQ[U<ĕVufS;2%쐮@~2<&yy+\FK Õ$^'LYaPd #`TYǽR/FrNaN&K$B`wqI*i'Ը!e ô[eyh)a/&^bJLBO H-*ƣ)!kjX:Ң #:Krq_ۅrxcWp`isԯ17}LᨺK~d]ya,H٭!|l!WWYǵ8DW2S2GؒovkWx2b: ۷v4wZ_vۏsUImd7B(̥;t:THK~*T7[Ÿ}#]`QysC̑[Lx߂ځS#ͣ]D!p"K%"`V6'^?!yVd3~}> .HFmx9G8ȥ;i%~|qR+cP`V"݄NK#sOπ rJrV8raAд!>CEM#(r? I .%2!'%:#]Ir|ԠաpH#EZB%~/~ ̀3&%zkk| kذee9iUGq|{Y;Fv9ʠl"^^3|3-4`.V7Au=4U cܘ~!yMI'j3ZX Aê8g%`b y>󬛸z 2Weʅ3pjK*F|P\J1.0ga:% i{Of7 ].~%~@#*]S7ȗD?mB [=C/O2SI -rҹ+>X̻_ :rZ n<*d,{b%}Uq>*.7H˃a?!@U}kd><|JPv-}֢;ܿ'G?Sĭ~ k4ط<,CWX AfӤk|(胀n~TOKxw!tRJ7#,nE;PϚމ-PA+$ َ !g^L8LV> (z}Q"tn<%##ͧp%Yup<~! +-C]p0sŁV+K1DMOiit%Fsr`v{r97,*nڨf6 ! ː4 ,iaIix+,NZqWmҽ /،T^^cʼJF?4 Bwwħy%j׀`1NHJu&>j@w(r)ѧ۟qk/悎L.]Bf>]iWkHλ(}Y5k[Ɛc~lѱft'T@ bp[3A׮p|l~ӏ CTf~w1S8_L:*+4k,F0>*\#K|G-E/Eܝa/ Ȝ3GР#KV 2h@7?`{gZ/XQgUM(8u2`q9LUBdZˏcÕ7,͑: {jc[ְ~[`PGp5͛F%uȾ)s,l,_}d}ޏŹ)Raj>$)[\srǑ!G80%'ݣ"ʵmi64}i|3O;t?;Q4Iz;xwtepT"C 3j/^'ta,] Ĺ'0SB(Ʋ+A7M"G?5Q*'T3X~812߂(Orf;'sH2=ۃ5)JvOZ 5Yxsކ"f:xŶfe߅H2|7~&,n߀!7&;iї{f R@|f/pn }Cn%8^TlY ߘX]MxvE`CЄtSYd-*q`/gׯdr &,BS_ #sjP֤qmU3`5Y ≶o>v$@><% +w~`PBLRfx W0:R B WQM/:Oe+=݈P )-Q&(/|̰M}J 3{ ΀D} g΀R,t.:CأMh2NeuϾΪC$% lTg h{)V%%3~TnrpD*VoU h, o9*gC"DwRyg8d4;^$MGC}Yˈq 9t5]_d,y>RKb`lGxF*PՋ~B Nb (Xt:kÞ&G4ǮDxzF&nVJX< w MJ_TՂ=tG!ZplTICPC075o*͂n5L.oIf,i?cuV2u%lm3^2VJ{]IfFavW: h<1?w_|4j9ӔShD8U;<Ԩq,kwN*_m)Y n`5[9ږLei^<<߁Z2;?);}錀ͱ:GY Zųb,(YB0Оdzc׳BjLg&#U ԰j|e+z[wGǑq0_49*I+ARͽ?hRR9o H*A԰WB.ޝTm?'0y`1Q)`{n-[x\0wVV@$2i4}_(3uKz拂d6i/e{H@?C tv<=m iIDI,UC(@?^$8iȎ2l%=+B  mll'a6塣i ≰3ck f@/T tw\^ ,_U#-5ήN Xrp\NX׹4HE.q! w=6)Ј/e#LYgɟ.q2O( ,K $t7wU`}cJ tp)l6 `H*7ݤQӋsQQJ8[?cgn_ Ӈ |Ikum= tdp ,{ӹ!E],G+N~mĆDS[?TVg9M: i,*jK^젒읅iiG<>s\ ¹תeّpFvj ޾j ʱN4jk#Z=@R'1"QX]Uo{r[%i Azg_}<˂6op~72#6J`x*ܫF"-Dlö&F6¾RCùQlߞ_?v a`JwVvNmthD&1* C6ecۀc0%5$ust⾉{fYC[!nBp UUz1$CR5(lێ,v=d-Az2ƫfRq el~!8UGRiQt{a(lavlNQVB1 /y%L] ns^fMgo\ϘTbZgm瑘gZVԳU1QK?}+zcVS2y@mMC xVݒ눶$ ˱i,?Hmg"uc_b#-"= "0ǕM8=0B9az,5B,-*'Q}_,}QW[/pØkcxaȲIA#V|h:C<4.v%E9=FJݹ60IÄJ~21_*w{Ѝ|lf"LX/ChcCZ!ltI-Vnm/GP!KH-oQxeOXSq2~??YX+VHt tbrf`m$$TB-}) aqNw'yx_[E9?ehS+_E'Dz(F0$+՗lM%pR/ gTpQ 'չQMQoNTvc-k'XҡZT&W ^XusBqfMc-\PYAz>r!ֵhpEqI]޽d÷W2hki@؆\9$,Igzsa,pIhވ8=#1 {F\K~)j%@&W(erˆZFH\Vo'oXG3#c(pw13 4mFD1r;ђ5oXzAA#[&!ߵ?eD.KJjjY+BvSe<áW[$EXA&*RO>A~hf轺?u,M&U2F#f~V#Tv:V0%2gPfw解r@o'V$J4%r6LK$QZ#MxkMkɈ>dr"j}t*4fU#8$˩.F S,D3>ב(Q˳`nEV7󾉡.'qP)ˁ+&|ޮ ֢E "nD(|MD1ʰ#[v^UGd[z[?7ť4OyNf#@4Xj4U$?Scr\8TGF7g QH G1VVO˳.XڋSl[1>Z\@]ƙKx!'h*fN'xq}w!{e{$(~J}C%]::ЅZ%z]6*~"m|O4nL'?i_.WAM,d[WWFQ>^f(2fAȩU)H;fGA&!¦OFu1ˁ%] ?^]Y -oY>8v5AMV̹#҃kZԀtAJ[8wիx/ϗ1WĘ\T1ɰWx%TE K}4%ˈa*_@+F* mmkہ6t!_FT"TCw";;cC9GI%Ψ۔B٭ρK,gR Ĵ,1<&GVE/j*Cp?@G<5}4ȔN)O09O&T%_3?o7C8&FavN{zh)L+iq۫DMs=u&7x-"@0.Z~O6:ylui,[B>,ECƺdf8!E8ЂP"ccoZf* P]BhۆF@9Mѫ{kZ 1^(|: ,!AJ?,7FmF;m@hRDI ^;/(_ ڤV.y=,3X.qy D?Ae$r@M4si0?CO⿼%I T}]ʠrbS@F6AB_ 1hEitD]ΐuX2ȭ޲Dn{&ќLa>OcdM\(XܹY壎/Bդεe4!AH:;AtMYS޷Y`f_Qh T`=V:n_^.rje qL٠A DpT;"+:6袳04AиE(v X{cԚt6^22 391 %$3=[TUeU=5Nx3c/yu^D1X* LjQh}Uɥv:O͉6J!UܹZuǦY!;2Β Fc)ԱT`zm?_&+ŕm7BO:NW[uLC 34V|Lk\1`ґ0XHz9Kt=@q>t;,vpVskoN\K*j,Q}!"#|2 #O9,`i`'ήV7MD U85dL"sAu,w;ɉ[@-\?*|{nMa:*h]AևH 8 r#ۙeJW tuzt&[A &iRMat%U VtZ!׶ kOEZ=4$בQ_0A4Pr;ƀ"n=wkn8b(`lа懟Ek4ķI7vRrF;)l&*1eՇ^ ;W?RvE^dɭ׫P(`񴭩k_?$[jCV4Xomυi#Vpdh|1m3juy2.?F-Q ;lzoEN$NQzhV_3[/}#ս褍6Ϟ] r~nyrv Vѳ^F_*z[ U"UK ^e'T^K{Ao?3ϛf-%[Eb-QKBjVHat[.pv=5~GyHhNҢC-P W1ҥQO{h;i1ȫS}݊jsAHU|= D/·s7/s[&A_Hj/cv6ivmfN&t)=EG Iv'{b~beblV8?G6_W0_G#sv?\nDZx/962C,CBd e笡ZuyZ 9)9Q2 i&j`4HL$&怋)EtK@ݦ `IwmoLCOJB 4~LgxصBfH-:J=6}J{iIYp k(-9lgI䬃,K=BVO|,ZXώߐQLso("W7_ B [3)SCҀ`ҪAc طy]Vf c#=5P4O ?Ϳ/fVS+5!nJr+30Cֺ6 ў,X\O~U1MɳOC?E _;ƴ+OX!?F\ G`(L|t?+Zk/B5l)ǠT:@6alᡝ:-gB%@) (4˥ʤtw߇a bV̌f0δfzaoshw9(S("yHXO-{G]4b3D$}' U~l'=a 9R0t<Irx$xa,8]T7Ǝڦ&0펆kcnkjo%"I+w=tw ^2- V=x㥇\M?xR+(HpC2KeHT;/Ɣ IPsl_dOCIrp bz ;SCo U$O2R}10yk{&%{7QP'$c ʗLLa(aY/Q~]¯KtUřTg>4L.BIpQQ,Dz\WnƼFAc}|}v4mׁ>sz''W]6Ա 1[:֕mnǭ"l UHt'1ڰ>@,c,jqVs xԉJJM_S '򿏋2gM"fRxmH#dUAnDEIK9C" 7|bŃHbSB> EBFvCa2lD!b}GٜD[GIУV q8ۨD|t@j4S]ʹwɡD5I1u(S?s+dՂlkZ:#d?`n BЕf%,՜aXu%s[_-,);,zz R=x4mMC{rwY)Ńzu%1WL/'NBu?c*;?%|Y";fJR7AB٨ 5%vur lS҅ӧ*XNa=]Yb{h9-IN o%X$1Sϙ~Z`W&uC!iit Wy].5An793"Lb#"-ﷳ+;bh=K` +(Rv+m| [mu.Yj22O *aL~m<8]@-sy6WP>T6))KF\ox^7&[kSLa"2:k>l+ }DFSӡ u{Qbs ^b? *:n˵]YɊZⴡG#\"gEtvq> 7&rm!-Ń!T l(D} J3  7ؑ!o?gw W,^p2R=PsfkM#G)$kG>.,4įL_p5~1&D#J]ڜ~Ȇz\<:#o)duq_OAɡzʊ kI%DU'S ^;k[|_BI >xdam:{/!'8߿,];)_&P TbTAb:.̌Nsk{XcbY17_LlpxFU6:vTqs8ܚCQR}&C|~;R aԝ7hϹpl$ݚX'㱟(!@8yn(1C{o7cV1mHn5 $b9 #vo-5}Vʇ]+7fv.ܤ -c9e/C=`T  ЕKBQa.M:%ۃ mgDWHfJ8CԌR7K>$.\¼-B}3kVA1zG.#v4wyaMjH7Z RF.86DڴaMeu,%V wzn]Pq>s_DG***(gMŗhA2/: tFqeP S1pW1/!?{݁}C>&>=ُOIz[].s㍘WJh!(>+DJ]!K)=)آd.5U3o ͖ K~T,ub_ g;s2*%OVA"L5sEc):@Ӯ`oĩqsR| ^j#FvQ}{[ҷOԊz˘VOجc|QXvbjsUjRmUbW<4BKAa!L="qJC3gz|({ v.21+ pBT(EfpD(mKC:v[Ua[*@BP"iN{̹$ p2r8*͉»hPa\?>b&aV,8>J[c/uxC?ע5y`.'+F1SiB3d~C#'\$KIؑ!7yA,AL?R[+GTU)yqM'l[4n(ݦ(C4;̐N ?B#' g7ڿ@KP*bfs6 )FNf*|aQfޓuӚW=o- wvkT3S<ǣ9 .fj~Ak姶On]?4|OX&1Ah -hC1. yd@jr$|`ERc @\iD Mæ5aR҆n4ʹ)># C-Me {< q8b)$a+6dI޽wWδ AEV1`@ *ykڎ-^:#N ~lYB:"7F|uxsXr[xCpjXuK^7Gמ }d90=o\<πzB*F3#BO',zz|:9kkr[-l\mTWCZ3umuxItLrX.wb=CHS2L NˤsRbj熇;d+w6 J) O|eG-df:h4jYw- O-eq`#'؃0zTQ1#V iœ,#gSWU@('cq'G;O'ڰjDOӬ҆~sKgiH%j}&yU,Z{s`ܷ)m'?ء0u ˜SLZ_ͽ$`&_KJ1 H;r>mVX)^oT X>0y0a*0em$?;ܺs4"m|nr~$:@6&WģD}Gե9Uj0G.!~mJ},]yA ic&b;6^;ud3b 4 %|ㆌ6ƞ8;XCeUQN$ jae>_Ri~FuF9{1 iһkӪw‹ꆇ;j(W/5g ݸ F#-^_ gw;8ZGYC\0:8a䭬琼W-=f%~ǽ#L#+Q̅P2&"|4 PpF緃S(G+( 7J<|{2' rd #w~6 pe200<6*Pz#t`ꘌ! Ņ|5u%r",!y%P׃k}aKW7[z0VXEH2PyƤƩq݄dx~)!eVnvVRaT(r jɸXE3G4@esP.hA%z"Z ݷnE8ʒkJe5~`ᰮoŅT΃<A'0}2 PLSx艻>~7" p<ո&a8Vt3 Kbj#_3? "#{Va RdӒ*jg4$v:IyX@E4ɞE;Q{kx"&QE^&Pc͡=tY%B!c/ᮌ(٤x{[w=\pT>DQ.ȃ4JgsQbaUcqM PFMܠ'r uDC湪fֶ-4UPvY5(L&7p;j[ Qyڟ3+$Gt=/E~Y ih׾Pύ[@_$52ܬmD&;$8a)lՒ./vn*ok]pCkq"Ugg;CB9;hd ;/޶?l?93Ìz[(5vLx>̿ZOip@Ě8NEuOFcvytz-Dam[; 5Bs>j%hr /+M4>T(aA5Cj`^qN|&1FD3̞w˙-=g &|t)zut#|~rծ5A5@s5jݕB߲TGVnר6CQE!aIU`REN@u<C-uXi`Q@9Yq}\MgyN*٨Ѓ"%~ą!&N1>AOˬ*3D7`ijz($*z$c廵]3˩TL$܄y6";{:]&tY&(wN̲ȈY,'O,sGY>eKvdT :EfViW}k"@Fl41C~CP^زɡX }?ϐzȭT9!M&hZC}4 :Լ$o4g`yzCXqʄ Y!N%*;G˅htopm..B5!j)/i P霕 ɯx_XVp$'~+K!5GkAX]!K+aw,~6}UcB/RGP{tY$)F8/eS`لY/>nuYU>aGCgRj뮐rMdwڪJq :^f1L![Y+-B`"\]r#uLjV7Z+-ܐ#L($J LSq%.ZjA_"wi<;Pթ̺^q{bic],6Z8z$[7]ڲ,T9W~-Bo_wW^dHDD Jf0-x-X&k ]>+>8Uu8X&`boV>ѓTojĠ~}-ogy(w%pV%< ZXq97#u:mhXLY}eʴ"DbÓ%Z+&h'm6G~Z-m#0$}U֢ꥣw%8%/KNUEEy88g']wYEMnj~ pryWg.C)D=QX06\"y)Ѓ0a O+ڤIs0@  ߆K?I\y;Z9w }qνx֐hb;9BvE빰ʼk[as $N(?mغ! ЉRs!*idپAR+>ɐ) Yވ]e},Ȧ$&@Pz+?\u!+ rk2yru"U+NڊZ!fL I6cD5qɍs*;8+DQZVEW Oސ/%I߄;'Y(#EBLb+*b.sHٻyڵ bCI7-ȮxS'p.Zٔ"5u8JYq[Q{WM00 g"rIDLEY0Ip48`+T<~$FFBO@~ VsudoUvv ƃ+=g~2Q38)utwF\aaN]fuͬM܆TєhJ׊6iR= stw>-EU/?#g=+&YDÄh)5XڑkyhВDtḰXifCl f@9# ύ@f":UZnMc 4Gb~@~VzZ ࣢^3ɉHv`-l3&YDM+\fnւw ?yz/!$TgA\TZ 5U`dm :}`dW#TKb uP$հd%3m#&s/6>r5:_8LH 5{lFuB<"SX<]JY>Y|Ex.ÅcmgtȥJcꂘ^ێ3#-Dk/7!δ#qj@q$Tt`h& k95)y5Ux&VOԪr$(I-_3ѧ?ꥁc^O~`tظ x64(nu\a6&=򓥔5D?[|R:f2QDDB-oZ,J7秧&C_.ç.325$Zkp2n=X8alsg^(L0#\ 1 (ꮊB"~StfUNەi][dߨ Q~:*ӏLLr~~\_c#KV&UØT߶#%It;wFaxߋ_D|w}HG]o[I~7jQ"i/zNzvfc l˵5ʧJͥ|v(um{ ?>Y?qި F^޼a/+h}U7ן2jqZҊꓖI N5[d8,yVcKPtǨA/b^S@W'~h3XgE,)^\ ՂzAPL#+rf5ZGs UhW^\0 ;!2jK8\&lC'j6a4#3SQF"[G0H>pG43`0 Ճ)i>wزZPPb`^ZTTh7rmn%򘕖vFf^YTkER7O;7 (-1ַ2V5z_5< 8X%c~\D'1$[R, o' 5ވَ (UkC [eJ8v,B6U/-4Ji'l%&Z8*ҵ jZEzM6U nW1>-CwZ/IO3~Ջ{,'4!WN"/^8R3^YWi/ %PN1H+hgoi`᮹Q | }%[|`n$۶B i} j~V jqRqWGW9V7p9&x$} UyrtbXa,oV<).5Z\8Dk}vΝ(F|'"U  eElOHZ/O'+x ۭ#cv-xi_"e)'+[Qz[\ś´,փ %oE>|#n\mS/cGp|BJ@S`υJd jOU5 xUdFLR@Q@z%(D'QhQQ7~(dr6`V"Sc^.F!6\U=`͔P0)MҘ9Ubtgׄo]:C]S?L޲ 9E9fB9r , ҩBߝ%vOH4GCCT@y34Ѳ3~z#s|naSUSe>CcXMz{P:@3, 35|(@e̾cR@tT?~MM8gT]G.2Fs?՛6KX9GۤM8҈^ϻ'Wx|yBY ԸZg~6 KlpS?+Ct0v̏\YE'/.Ȑ +D*'o{%v%S.COJ\~#}VO.{ROyD$d<U ]?_Nd}Wm8pT/WN- "G:VYt16*'>nB03ntDW T ~J>F~c;!t)1iMu8&TQ\-*%{/Ae @^Ji**} -R:W\ O6:n Xٸ4LM8-:.ƁL>>+af4v, l"rO("1tSF(fB{Ykʜ$!-X[OxB=l+1!}^F@_KY;P=N[_ 4՛qx"l,IݝGV`vBr9s$ n'qԹt[I#aSgKFW>v͹dLSA2M|/Vt6QAIv#>M|st ;5T$V;̰.X 9t[KOgDaR6DY;^XS))x/77.\: 9fqKi^lcn o&~ JB\y?x?K~랞|=tWq9;C5X]A|Jr O;oReH "iUn"w DNN|\=ֲ$( Mҥ,$%Wę7,Jl: 9#M1J@#Z:/P&ALslHy]Lzg&YkycZϤX!UFk@Ng?7T5},xa(*klyǪ&፼:|Z+WH-Igh+( y=YYAVÀ&G2uۖK 6R-m4;cb]ܐd ?.5ߣLNܛy_jFlJtjeM&:I̖íQ5i%|:憑|V5X;n@Oe>gF\VQ# -w&G͑ 澉P0Tс8'% C},q聬7œ&f[{"vNp`4Ymzj4L1o M7'Ɯ-4<(oCj(|/xx h|O7(rFS/aZaM4碎KW:'Gwrcj8)u"2" ^P7zBLk6?/i,t&8iBsrRFU4Q^f/ڇ ]5|Z 4Q?(EsŃncS'0p~ )hTaXȼ #[CW~;[CX$l0O߼`CMl+K~v,=ߖ3B]g4^ݦSf ێYrQB(f;7(OxGTTզ\0埝B-;LwB*"ǠyLw]sf:%ѝ35ݹWUZO]H ۄOm71@,&_L9*߃}ş~+(|ݮzʗj}q<㛓ˀ4aU2\LonXQCS1~RξirH %Ðg)FI ڢ ^DPbͼǁ4M=Z)6&{/G>AKFfݦM1H /X*vs#{ ҆% ͪREkވǘŹp.?DI1j VkHm\f 8s.Aάo#l)\gCRϑbJõAv- 7ɌόMZ͕f#"o 0gRW6/= ;*Z@ӹX+D2a"WNVUfDHmdiIUӱV{E֠.zD%~fu9"Mfe8lqUR,;{Na;)1Rk*P C 48*ԱmKYTYbAY0&Pm)`^~MTf5.FV9\ěr ܗ#P-DñdXgCi@SdiʝyK>Zu~ɈȝcՂ7&,#&3hLEJ;(EU:LP,dDA" `Lci֐ ͂ (b/UzkHt(Цcxj^ڕjur=zyNugu4? f[ ĺ8&Lsy 0 &1=Ľ#zw$ckR-'\تl!Th؞aW#_ð\T|몰?H!2˔,#!=YI%?3TB:߃V2mQv3Mؿ*ȩ(b~JNrPOy3@=3u"Z}`~? /GD{g=XHJu{h^L~ &0ur-~N: &toZVz@"Ad-0c E7NWĥ# e r O(K @SYԽ j4y/@8郡 Ѷ'<_Lf۹] N=Zh"PUӠ< d3\KNM+,U} |Ŧu%xtŔr_e R/JqAQhEE "38hsI=Ӛܑ|cO$,xx_KSR6(+yemlT*꧌k. 1a>FR XfnHD>vqӒd}dKWt<5^c!S V5Rp꺛rݸJͮ#AR%﫤8f]`APu(6֨:x_m3 ź? /f~3rUVڙ%sZUgt*"$.җz@|XQm}W -{GPJW7P eXO$)inc>W6.OFNʌ ȍ7TI[p;tuEK؊)oXձńTۛ1+m!ǟl@~s卲 9&ԊHХiL=_T)@>;뢻2G;|;-f'ĿM-mpuz<1XB~;VH g?ۄ7-Odr!|BX'dLNE2f˚!pZ~hMOz8֛Y0دYoP2M)n!#t;O^;9츏oZB ZTi@|tןgmH,ۇ؟p׆ :,cӍ|%Nf eaaI똥I3d5Ki%NñsP~oػPj,4_kN&y8eo*zFoT! Nd-Q},n{2tI7f#Ճ]Ԓk0>f"7U#khfO|;-Yj{^^&NA/+aCgAP>\ .X.kv_\8jCqo2[<-ERЌt_V[?FѶKIz-@2C2+qqUg*,ҧ`? fWe늃_l*a\CZN', S7i-]iǍȭ5̏,XqH}Xo&XJ^kY哞vExֲ OJ2=INE]a9NI*H!W#<4#TU:] !_*>[9yJ[rvpgz^y12)^ |8Ʊ$HIm:CKVW%؄{ҎMẍ́oHHCqȨCKoV6[h{0e~F>`?E]wEi[*Zˏ,V ]T!Y]|6atKm,=bQ0`s7hnךk -Ea5++K4YRѵ':ΈQ-qY˪K=Y%-BB\/Thg0}߽o%75㫖aT1|HBKHD&zgwf*$ %<C0߆jډ@3V-w+/ѹ+{CϦM 5>k^.GHUƁ4-t.0qjf)94=Tkf$SjGW>ϽA*SW%c\NBF$CDrRS_4$odg{2Nw|7ў+@j#bb¢ѺMP{<@DJ_|CrN2>mpn=P fpkiˀ\~0![`h0=]o%c<9'0I4Kj.Tg[L=] Z9bƏ^fFHri-;"6`~Xa? ٪Dc6Ou%p`vh:Y|u\apb,.^qtҖX t1p}#rZuDM#fZ8yQ)f+\|޼4&nhtjbѻ_|[N h2wY%_?({zoHiH1yB ˼>rL'ZX |u^_f^?cL Tɇ&;qͫW`wMqԆN3"NQhGB#(I.(i` ' TjݦL<ԙD6[φ"XUҿhK82!YV*շ<4wf>+=L'!dmx}iiݼX ym VUDvn:ca4ri[-=Nke*r86-{c+#s H9B|.HGeAg+!)N+O@ '4mLB(INbTZv&P9RI'P8uLKBi!Q t3ј9J@'k! =l3 ;UR rቸ.V&%#͵١Em!F,+N^->( VDɫ)!{L8]ᑆ+1B>o3 M-GsIMt # DM[LwB>9M,L̛vo- }#c9HuJbzH(:\HZŮ JNaX03gf{{#m-NLO'6=4J` R $3䃁r? 2k7'cXp͚PtLh7x4H3o{g fup41U!h:'>{*p L͘TcyaЁ2ʨ+8*(d] IazJZ!$5}`r,W#M޹R$ dL`j(ᔤDb~ [c'dy#=KE]fUIIqEy0UPmW\0Zݎ 9p{l:kum茎pxdBf& %_ox?PN@xvQ`AmSjI bircȭL~7JmO.G$/,X崬Dmu=te'{)saLp|Np͝'JM%Zw?9CeV/ޑ# .:CXl*gqFLo"dz- ͘ Q%O_V pADNdWϔ1e.\2*h7vҷK>SIc"kUABjUc#at%k4I~*-H,Kh27j6DQsO̽ HssyDKcsx&`n+2 _dQU&M9޳t2U! 0*…ѼYO>m傶@Iz+ 1%gbg'XHzxqIc m_lz?za"$2Qh\ѼLǵ)s D4 oSз%Kà6EϢk5/Si57y"/fYƻtE4][pc5zjfAa bR(DuМ#oG.PH+Q EI|H3?;u؊:-ʬw}A9yqzlTB܋d|摲E_KX@e[t7XI]iL85><ͩ(ջ.IZgy" \@;89M^ F@D)-3^QFucLDp`/LW{Y4EvOh0cdy_v| ϏNW^/1'* W>ύƒ|5v-x% /|ٜ.z"K[`8<\Ϛ{x : L> Ax>kJ,(6뀚8ͱJ)Ra'Ό\{'Vu)@[V'80r.Sx2TgPչ+c.(ۡ_ʋ,@y:i`HnUO7= @u;lqn17^޵.⍺T(6N3]|=x{ n.p`+AIa%n&$A/Absp:F/9LL?zf1A]o"C (~}QcŰ`zMů7Dao5^\=!jǺl`7$Xlk0G?M`k݃E2<@$Jo$/o%^Đc*GΛ(`ϔʥAmy7q^ww+*0+hڙxW ,ް_j5WNF'sIgH㫈=5L`v7{nxRA+ԗ4rWf2bOSJ$!h\j doIEkX}>7lF@9M~RdSh-@ޣM]^3%u^,jGnLz!_:ldC,JWkfHMU(;C}AXwi)a04B}zSXnk)d$mڷ6ދInڸ"{jci!vS^wijXXOǟMҥodx ¶ ; 7rd2WY}yO_Oc)sE5ɓɉy)5yOJZ#i(踮yM3\P7QF'SLzəPjy 5n ug"kRr{T8SF *AnY̾*[x y*]RG}$FCqe+7􎁂,XSTjAf'TH@6M<r *-Ψ[eglSٚ ?CC+#y~(ݳG[2'P,*1sxv5/~{07Z*ƲHb@xD}ϱKOg`F[6664B;n xSЌM$j]J944+[#d~~7#iN\ovXuh`cqI:5 EQU(=40J/KkښAĬy_O#2Vaq;)' [7 +S^<톁ii ΐ_}taKZ  ]A +70q,pӷx)/OqE1;^8 ,H޾{#_ͧ~eb4 ERlڂ67)kdna+MSY5/^%=IHD7"yI9Aޚu*u~榠 inl c9ʰ0ݹP|w`&` tJhE'џr?/0>Nms$`ZFV.7<-{k$8Qp801K,f/NID#U)N+]3㠟<Գ~+Eqo[+1yjUR-IQ[X5]0 ɐ3dyȚi9ZLo| s}uD-Ϫ8 xA)suf6e˜;v=ҿLb0YC8;S! 2@ӥDjȒt?#!<B8~%Iкfxlq^:9DEC b?`;M<u8 q%4ZYw{\S -ہ-K/#?$+[,m)} q.!8>acP ;iI4GgѴU[*pE̔KZѴ/3FQTx a}[jnFUG5븛jUoQI&n.Nf)o)<:zRlN:GX[ !fZ+@?vJʡjx;ZS9ZF_lhp}T_Ƹh#lA@5aX\-)̋vpȐ[Y 2t=@Fjͳ?n؝M33z'7CpIe}.HRiF]R:hYU㊁N.f yrNĹ5~co((ܴ5nel2vRTYNtoӎ2YZVZ'ؘs_ǿّ7r/2&2o\a0Q7Tl$\*QGlNJnHMsF%Kɤ򚢦 8Siaz͛4)h9um_G7OT݁E =r}d+@uf`*Xph0ͫ,=FӖTaF@k)P560 "EÍq1I"c\ocwGƀb׷kMBT |U1 T]Yfy@2^ L3+o':To&TU>LAoߙ#ڂϰv!ųdwM EГDOP@PܠIFfԎ$ m^YNk8inWYfGyϤTu˜,>xFk`)R5[2pj^=׺X0=icƷZ%Ҧ*!D0$PsF',7P;LTFޓ' j5^ Fz5rpV PnԺYAHW3DŽͭ*ٵʓ]+'+zac6L6`F.D,m;e??-UYFBF8PΠ>Fq@|F)i~P<}Ȋ?ݛ$Y<AUM|s8GGj+n_;5z6w$d۩xZޫqm[͆ʉ:Z+1Uأq$"PM3`S}rL~y $2%42ZnuC™ZxCdaU&n?\[i֗7]C`lČ >bAyHܞ焙Sb7xQNb>i~YAsY9IBEA(3F liaQN:@dEZ=Kڂ5x#g>THf88٪_IVmׄS`eaG͂ VˍSqYw9$ ˆ "Cz*CJ @LD:t:=a3rs޼ 9NS8YHnۚT:Uaj{Le >z3(A}UٽT2- ?c6^SxKR3d=tUi  6qxX)T@Aok$eƟy=18N˜_K͆lD( ]}_MY&$ԥҸs3d1ıxAN/-Nx[gQ Tg֬\ SAUk ,lw?Qin[]b}ԮI.NCڔNDRѤm|GDy;)-K/#P)j;!ig8Z#5ɵɂ2بÕڡvQ!=tBk+d~"+_;{u~` zdq%-dXV? *W|1| ?A4a6C;7 2׉ ( *WDTA"%w${J[jK/ҟ~b'Kj-,{@%6ZA)l7(Sn/lyOM,ۘQomؗVydɷEwZF!Qu.QW%uͨ*̋QW0S"* ',ĝeFaA6_rF;( (7D!Wp%f5-|}06nTȴID炉W tgiyMkG7/ UCWi^ Bpσ©@\t//k SS89a 1&KIUwU!byfڕ1[-vׁw|A9A(a\FJ)#lrjX[ 4[eU"ΠZ2%ɑHI?ǷCfmZ7b# eE {-/!$wv_5'@3[bXjRn>R cl(9plkY13.߬肼 $5m)L%ؖs:]~:1%ӅTfABsP~/av;s,9$oޜa [`dd|Eaer_Y':B vx9?l|8TX3/j;&;|0ҨDxbģI$()lvP v Uw] Q} 46F33.3PG$9(%t6$!`ay$^Nqz RûG}@ƒnBP#_`>ܖTTI%hW'/Yd6X/@,w_"~ޯ32ft]R*O8G!o%Ob7ۙ!eض,Ke c!zatZL`X@mJ&P~t,PD5qIq}xM)5.쿗.fll=NlK>$ftTcZw77^ ’wIOCiFo8"َ8pj9P'8r3CF_B[=pZ!Xɍ[!Wz0./?%S7ǃ`cnTyh^ RHD_?!uaTV<5񄓽2πޢwS-kYԖSё!Hk(f}!Đd^'*0戒Is{X΂4kݑFӤKL1W.CѢȅƄ۷|4QE#~'%89jDH]ڻ4ŽD =BI?7^~&.5#ҟn*ԍ̿AbM2@q}֤]au !nxڢ1DO#G l4OsS\bS<+c*ɸ;FuTټڦifMt#7ύF׸aC蜻u6m =d؎ 0Žaf rJP_[_*N2ᨍQ |G;UٟvP6lŪBK|΅qvBHjWS.⠐}F2 CگE" 8CNehD,*AC-%尫7J_7x6:y%T(XA\9ZJ`5t0{Ejxl;yXOTNs%G?C|O s/f kۗL9250; (uu[k=:5dDY^/QQ8!Y*̅vׁ)vzYW'4D7iwm;(&8q2?1T7$N,~} ! u[l~HU!@L]L S2^'3Ӳ GĚWכ;[\}eda&o;0sV |):I6FX.kM1 5٥\jU =AU\i(7.(ߔH<- bZZb⟽F ƨ) UGܬH}є "~%,GI POos2o|%SJ]e M\ "-Kf[LM@)9C8_BsE$JPW Nr3Ͷ P'Arz!3?"FT [Srz UBA310LK:{nq=^ 䥿Up)+פ Hfrw\9)N?jpPSawM-J)Rp 5cw^aK!:Q caxg<-^xXoc{ CAD΅o}HnZ=(on4XOҢJسh gEkXIoDUi]Dk q^{+uT /ge2EitTl) HobpSwNh~BI-Nbb\Sl'gd9h\0Θh /ok9eV',S} "pF I xQ{[DPYu6i4Mip{5|kjzM! $%2^aW+z{o@&LF @M̪Yiqm-l}L-P{fEIaOYe'U_BSlBbkCvڙe \lMfA9P;j'ՁxAY+t- kq0!u[ѥB_{Z$ΌR̶2#'հ,Q?<\tlj"Rk9 +$y#f΋ʄJ+ܟDREBoEfm@褐=}z\ㅤb&5)b˥j MP3XܤQy:-Gk 6^–Zк}HEX$5DFݬEX@{FZ/@x l@f8rI;ķܝ3/l~.X}*Uk d}H,1Sk =mVߡf"^6fT60@EP=8]ti=qS+>6\K^X<5'YkN"'U9lzj ;|q.&q޸|n%FEO5$ >0H@˅loܑ rԾHiAP,3U"qĶVmŀ..HlW0 7e7#v73AT6:E>](,¿ns6ķT#xRkS#y`w0q}m%s+M#35+ n72^BN毫o!y*X$^t)jLigRđ7 ˆeS&{9? Bp5p=@N!(CJL:(QUy|Dz +9X&kcAX!^+&KJ@@IIpқ4ǣ47zHcsdHXa1y* ksy7jT|}bs΋}ۑ~dpyׁe-'Se "RjRM md=d=)ۈEj֋2/҂&w,"Stt?h˲{Pjp!|J qSfU  X#J%e<$DoukUǵNـ~tBek*̮=Z 3~0f^ ^PģF=r0pxUnh&.2\߷Рq$]a< !a)f}ku7)QQ,<䦿$()=gFLѺ@VPdWXj%%x00c~%(1tn=!Y0nV=y&߷s4όYMIٖs$8R \2*X/;3w\j.UVmhܔ`1rMM2o54'rX:(ԻCGee΂}ܕ#D^36"%EU_onx HbEpWda ƮN͊OxT:_$3/^FN(v>Ѽ!ܚ: zX;~wuVR'^D qɤ*:l;FS ŲEoMd DvPP_CmZu>0somX`tNt^e0j}̀6C81 N7Z9eYWl\q3@v7 .tp )q{w?>㣄hD:4(e"/b9 n|G\rIr?%4f^v9pD +G>Գ 8EL9)1OARR%٦NMuuhS{|4.S@_'AbB D].H4Qpjp*<=l-p|ݎl-{ &,m3N cRm=r]b|KC&㩶yntdC+=cɪ\~+XW9`Σ3{1(b$4q A7j{N X|$5˫BLV.#FXn#&ӛ9C0}W6USXBXBu%4y"k0̅`DF`4*Ci%Tlv/̰@ ;n1%rp~D]/#*5ź%JCGU82KQJoj|#zUsAat__q{k-9_iPɾm#úe0ƔP/G;@6 i36mȭ`NG6 b$*fL? F/+jQ*J-jݦA8iӾ @"{CX7)Zk &,RHwd#+ջ<|w\`'hȺ>2C)n{<ՠ7$ڳB3ze/0U'^2!F!P lΞh0u\Sfmܝ=vͽJH!1nv?0H?Kp6b{%#G ? 6t_Q$A^ /hzA)&ēu)肶?1:@<ygkf)/RB@%u;MZw4|-׉L>c`ׅt l f(Ơk$s.,^42F R.Bye [CU'ގؘ>] O/@wA =P@I&?Cy.Ya4"^2Eܽ0XVnE/P S}R@^ڌ7U=hեVy|"LsT1)1@m!$M#Ksu۸ {?%A)oZxܵRz-6!34-{tEMlEy&ɳ1SPWı zs'x5λ#vԊmLi ϵU H)?J K1p!GB[W|f>M$[c.s%iJî$.!`0ȁ Z8Vĉ\_U_I ۣ vҒ/PJ*pҚ; g*ouj%ʼB<ᩎ C'Pʨڨ`̫p. )ZEy>\7$/0NJ Kf՝ LP/HstݸAC%ڸNcpZӁW/'vm# A@ =pL-6H[BY1%V"XBAj)xɟ`tlsYMeu)sX[l/KS.Χ=_JspnW80^F+(FSm_]L?>Rc.uRy^nrǡ=j|{0뼊PZ;U\CLwid[~zze9CfY12`*K9Fx%M R)%hy4.<8=p%g>èK*.dY+/ē^Pv ˒y1vѢ$J( g4C}ho'tu9Y\o^ْC%0S*RbmF V7ak&'IA0Lj=Fm׃ `mЄ]]vNb&cp󚦱C)Nq$xb0auY[yQVPWkVxPFI$5x攢 z V$o6 e{rI fXO٘|cʎ>Ah EfuPgѐDF0)'2%_5y+ 7f&9;&^if3|(y`淌6\({~4ϏKo :|$0 (cNV h*T(5ȧ9'`Zx[/4WW)m\^ە[mfj(>3rDKke5)h~ԡBLT,]sj5?Q*~^ӯ?ئtR8nV9$ Z.麤bmP `aU/ċJ8N@WھdG+} !h$1aO}P !mW[)%3G *їd;Ф1'(탬O;LA[E"WggIa+3$]3hzm꼆`oKcDG4C?nyr3pS_{4ՃRP}27z~ 40k]x#nq^WN-Xa4zK 27g]F*j J(U2t|~7fRA4P, q.ta}?(H ?e/]`x=7R]|S_~j2-%E*@yD)$Şgg ZVN#£[%L&P@Y!X'pBEo F;= qf>CͦdTMgLMq(qVLlKR",VJZJWKHF"[^.}?f2Ė/z;[$! >guA嚆b-<4՜$q[)v %7k˭-)[7(ɽQSq vdk޿s&XEGb-)GITn{, )SCBK`Ɇ)+MΜ"{/N9ĿTKf*mᅯ΁~IFE.JKhI7Yfjp$j7#r}V:HjZ V>:=a,KUR ׋бMryz KGz8| 4N e5)ޘ;bͯXK *p@06Iaݢ Z3wr)>pwk]0L$0kH3X N!\+-³7<>qАq L%2tڐ,Ɏr;(%Rǘ [r`:d V*.YfrD>o($6\S\0BB@@"z0c+5G"(AesC /r7 AԗQ43_ە%r7ےpnG`nAa.BN7Ă8Vz@OAONv4u!v rQKZM򬽭')#7[Li˘;bJ/+) M*3p:H+^Jk&bUpJ37( *bM:'}9YJ)݅FڑM>ևj$R3o[Ħ hFlPGQbW Hc=3z1 4HxNf,Ꮯ0G(t "=l ~X'|͂o74I/A~ۊ"+^U+Zu;g M-fʬ|II:`% }*|/_z֘[5C/à0KCȳ' @EIMg[?4 GRg%g u10Oa,Ga1'ȩAr" _&oX@;l[qn+(ԬgRuI:0H/Ik5UnbHqb-{ހ ߎQ_^up6HljDuڸlDgGTj7ł(Ԏld n28AF3`) *hfŬqON+OACȑA WV@`JtV 6Ozijc\x8Gh$@wCp6pD_(%|)* Z}7R)B1cRh8/,?gr;!W˓MC{il@iDXl< )Qΰ i#lY O@lǜ_QM!\@-f+/'Z&%FCR5uU5zRyW'k)P$ -l=d v'y/G\"joYNuGuL .jHs$ґ~fŨbҭTA"nz?%ȔBY&Rrt+z6Wf[3)2L1†˽@EB<ܭ on*2V38â1274x i?t_%S=G` !AI4: iiͫ|+'^߷!W@UEDKh,̜ i҆g,6`Z">CbŁ{&cm"r311ipsjlY0URG@ǡm,QJ=;UT FZ&V96@^qFPBrͯ6QSB/Bg{>weUNvZNy<^HddjعhL_^3C k dyg@1w9uIwr0B@bs8^s߶-Q幁c!Ēm(D^>j/0>~hcZJX" _TH :TNVKSkL"JDY'T/U/%XJX$~Q,'wávaݙܭ{ءbWM<Z~TSgAיHS* /DHe{<МMmHjjD6S!s}iӒGxk|khD7zNwb%wC?)jv`_f=K/n <-]eicT9io9?tlf`<(Ǜd/ 2jdyvՈ;HKR:z O>ҟ$Pg,hzB_U.qm{vMLg8|닺q|8T ,\EdS⢪l HTҗ;V1UaF# 72.0x d,A(0E30(OS 2(acngըYdO^T `zf[]Z 4r[BmqUK}#&Oۊ՟~9ѕx8x 1r}FSΣiB`LZrsi%"4U3L;gӅTl5!,wG4 =b,oƧW^n`I s lؼW ] p  i3:QoioFlxb'>Ȫ5 3>s@vYր!7zE]&sdq`3OVHɐz/k-6P3^~7{]`adַ/1{b:B8`܏Cq sג:a*΀kyi\f-(-J#Ś  *4l.C m.\5 L/8蹋^o4aYc`/ P0c:.6Ƀb"$%^Yf/~W98>k1 .ܪ ]@G|n ;{Sfyk$P>}k_wy~"זed_R,9-臑 Z#@o x QQE*(3ً(a 2cg 7`E `>X:ҥtd %0 EjP޽:OI5YD?ޡVag&K昴ڛgI_1㉲"mQPӋCʼn|Yb=*aOx$f鸉r- 3f.@w-sgh\>fJ2U43?sC Q~@LMtߵs p4~TşI0X+`<>~s-ʿ'!e -(&]ʴ;uEJ%L.'҉/*–e e0,n[0*pX1QX{{1)^ sɇ@wH{Qøg${y!Yx.GRD r>Xd5+{j"6Tǵ%3@0 * i!I_›,<b R(c'WьMhpNG\-\_#X)c o {)cOe3r ÑjFH-s&,y64l)9X5CfmQW.cP}Tzɺl۝Zӊ ~2܌ic`RR2z Z`7wo76OyȚUۋ+Yn Qo`-D4 `2ř|]6RL`tC7UfMT,~ujPƨ|6nɒU%7^x#5/0.|mVv|%߾Հ{k'rUooL>r:פR !}Rä8NU۠]BQ\@9˫,Z&~.{²k*']JCm')^;"]s|aޟ4/e)M^6=A_s03j&v 2<+]BXS*GߗELUP&QEHSհc\sR--϶IG($ )C\Z釀aIsrCqq9vo~-{DaUKWr l(Î7#¹ꢠ8٬bi/'Nx9(rߕ73S@bkz-AoE^C߭~O}'+E?TCk4u_:%mx1)_.[{.K߻Cd[$s-t&Y8}[H8BR%y^J$cT*sYo|CRl2̲zy'u*G<1>1z $H֪!:,غ-SE< oӅtyEC4Ur%r%/A9EÛuԺs͏ 6:/ld w[*1!gD|ğmZ %8=Vu-QS'I:g ~NW0^>Lo,uᠧ3{ +Y2ZzTRq]pAf}%ܽ0SCD~&x9q͜n?x&hL8 qO_Cin'߈Z?1#Sw~i$1 =~q7cmF *G.##qOHC R]Z[ K'e{é!mc-f:DKAZ1-#X[x֌i^u&7dV(%jB7>|j@/6@_}ɔB| $'fKMB^= !ˇrg˗A Էc%2.÷_-3r ~J(k6(*úAx]NR!EA3 [r}Q[!a?W[@C'#$jL"vƟl3q^J84CR%9tu7pӵ %UjHFtY g qxmxUQ<~9) SAaJߵhm[d ?s$e2=]E 4vxX:1 G z(ܦNS?h@h6RByfIa*W(Y01{s}FkbQ&<0$=];F7_ C Rۋe-"t%8[لiZt4CvM{%W5(S&@%W/CRie]C527Rϝm]tǛ]A~wV}=vS,"tu%ZXbK ]L(J> 4\gc.]x|Q> I|k .cf3w6`YR7u Oc Taݢ|"2bHv[$>,`T n]y3dcovAqv"b2=!+ (B7UARI3&{@#SBfʻS0C9z_>PLݻ݌y(.pX3W*҂nooF`5aLPu' [<F7t.y0nAǐ5us(^hMBf3PRfJGɐDP@+%<[ esZCKmqK; FGP_3;RɆ5{@}0/#BS"TG3҃3ĶWTJWk2{5սUn gbޢ5" 9cՐn.#"5 6pF};~|G!] $F7yS儱4 ;2Vn7G潠N3ih6o$xd}&LQJ:$EbD1z *vxd뭇RVPKQ=% +m=߄ax.)zr1aRq[+ֲD׽I' a~}.d9{^t/ji.naWh |0shUmNnA#w{&>Y6fApÈNQh>p8Z^O˿Mּ9/t&)?9::Z-jJL[Dq* >1ڿ!A!/Z%#lce3=t>c"8ﺊE܉b?7=e2o먐~˕{-͖:<iUlRʔb%ҌI8>$GeGY.k dc N밓au/Mh߽}pq)l9ӇED V=x(3ɏT-׭aVgL9e='z[W%OmGɬ*|s~4PcFQ)4AܫĴw/#Ğiқw@sO^7ڒ o?1壾xBipI G 5IAYlWW"I8,ȣ??\|$@!27m>= %~$qhPyyf(': 2Vaϫc џ)+Tm`1P|myQwv*UOz">ͼ@2V 1lRTĦZ–O55iE0h2e>\*$8K35ǚfW)Og- U ֲT}?IP5ʣY"&s Mta T$[7.?e%[N6EhV!\Ğ-!%2<Sп5@#֡w Erf^ ]G^Alo"|@,*4R7=out!4{wѮ?}@(Q(pCOVSIS | *4~v9gu;u&#]oڱsVG̒1qI;OصX([0뤊&q+;@ϳ'ѱdX꿭R0;KwX>^!cA\Eم~} aH.ʒu+6Cc9w/DYHiuI },x*Ç; Fi"+A5ć h|cxBm%9;ʻW`1ymt Y]mB\.^[g J2QuFI*8xNEJ&һko!%- v =\s<{0{C!~5" Gʌ>d+S Er9sYs0:nmd'kOFIBdm9 3j<!ĺ <(F$yq֟m/Dןak]հUko1gT=6|`}3N ^$%Fc jLP;` iOpB L')j,\vM%HQLQyza3+d ˀXbR5ggZ؃ P?k>ez2!kHwXo#bؕgwt7|f4\[DQ}Y( /5e(I_:t2g J_rEߘ"#:dZh~`:U,wRuFfXw'@[UʅyQ&N_ͶSz?<A -$q[W vԙ,qu?ZF|]q_~\_'a+K,w]bWWiphD?ŶW`.Or_WYe]$~]09d4VtAiގă!DáwBz8bFgt&-Z{F- BŖD"nb7Tk۶?_SFhV 6n363:nO4} Xf~|+$d яC>>L J"Z<>ŖL5UcMx 0=…ǩy)rPl?DevWf4?f!+|b+&N/1 n2pR}Yˍy@\Ҁ G'Eapٹ~G0Lgu˿ W(rEovғ^mÐw%2B{ݫ O#BM2S̴֘`/ap+pZLF8ݪ"0IcyF1/J2O{,K_ŏ WQh+Ԡ-Z?_WF5i1-VT*_6!S>;kyD(Eu1FZnɂ-'Pø'6T/:A+(!oal7%*W!G_5z0x#8K&Gp! m rw#^<_6snr:]1$^¿ţK0r#$c:Ӕ͌k G>]Kix:> N cq0vk$C%SbR"4B02w;SyW.QIGD×ًn$Q]y&~@ wocx[fI_0BboRtw 8NYWN/~&xGc#Ls!5ϼ#[>淺Ah MzjP8F4 QjxYx6wHOWx,W4LHZ8Cvt;W*'B02 o5,(ʌ#/uM|F /),9Ct"4P?>)CcBpB4aD)0"r C۝]A#Z;% 'SN9FeBGAYrMq]Wc [ZTR 9Eޘ}J&l&, ckiڴC!6J o>O/o>uZbn鼃U/\aw,;#*^,tm^!|2 ɎĴ\$K˄N#L3LNQ-pt1 .-H@2K-%Pg4J W.n+Cꡕ6CO? :!ئhr\\<kwQ,HFz/IۛH{&,ٰt#!k1HF=ʇ˧oH!"ِft4: mq.icQa4lJ=k2:K3΋_<YoǸQ|Ct΁ғ7&uO''bhL @fB V#c2}ܸWZaO'`_}$cX05aƄ`};."bk^%_xC4[</iXPiMDPmax5d( X5%8tPeȳF"'&|y.dc0]tm<NWj$ YkpFhGiXV1qhlc^7zho mKEvs[qFEEWMɁ˥XJFV r?D q ] KV,2-Ėsxdp8aFNĞ2*4-uSiׯk#|UMe$BkZ%I8QcP=ݖo CB|y|`R" j5_,[) IWB#Mu1| 7 "(qg3lW %]5Ң'lfBNRD I-J:j3Gu^K5}jn>bېf9 [Y:^}t<8>O g{%@^ŤP+;9%:Z3pST4TX@y;Ŋ ]v !1}O'U֢fZeL=}ebk]^@'KaTd]s*uĐ;i̶+Ɵ]-Yy dN"7S𭳙͕fkڰ4Ȩ?B(MB#|^6".͹5LCC|~ sG̔d࿘;at3$OW$5bTS- $$k:%.{CvXMye7h!YϦEf~yBO1kvmz&oRʻ""j?ev24* \k}~K/d>3,:wZη}cDiđ\mEiy.kF˘zvߞxsn& JG16Y8@Ar8{W)Ώg4@]?Xf ֩Sk*>L15O'{%H=w%Gv7-b>'G߬W l(]aP %yGHK^M1):Lqo58-[`AQ̥'f9KNK 1ݷ!>Hw5{o H1xcoO*p\ͪl`yrG4V @I_O3w(,i;(Ut~lb>G" ɖ;&xp?7ɠyKw l);D֖%{&k2I0r$8p1TonM[)wqPo>ʀZT3{F=;o_wÊ' sh倞7dkKd3cX4܈ %u{\[T4LNS1;CAV4-6ӝt5{d"S8Q/?X J[I4%Eq'U 5NSLv,*RknHC!i[¤[v$*(@p֑ҁ4r[?_%O‘ *i[+F_JH96f7sLnlkpߤ^p6vZ>$!::EqzQi6[|SO7mV$ -T*D <(|T [;\[4R? ~,ÒS7̸=GCFWjf\cbzCeD B^qqoڽX%DdS\ fP7EyZLz%D' 7as9IDd<^d_^ϕ<Ê'׻0|qGqar4$8(0G2d1j*ؤLA~q ҮWf{gPNTxJV_EOp+%#º&&jQw5ͽ qvSաVnfa0}L,%vCu8P_V1{H iR8P=x4wA:~m7 s!1Vr-s;Ʈk=6q?.z%­ *†Ú~O?eDы*\oPRhĒ3:dx[ɚ"iC{K;Q}uK ??ۀ'Pj x=MN*JZ{rm+ga5{pszl P8+$bAH)6 D duK\GCCpgʶMP=}-yqFrxnE.LITJNg5hd$g3o;P7㴇Cq!A OxnRO<{ΎEh1o9U<#:"҅sL׀yöSMjX$#R͟RbۨTwf,YQj -c ۙt>7of<(LR$|LTMP(?LO@:]I{|[ Fm͙qS;l32kPe?~'OFyA=sMRmȊlـK󗅫b),WQf5RV0-FQkF&g9rSH*[3R 9X_X P˼+EXhbgA ?> gSu(H)Nb04MSȳF6uVƓ ӿ[$YыĆ!,aʮm\C?/ @Tf~ҫq0[u'ﯩ"V:v쐏*(ĉZ5(;*Z6\(!uH*@;7񸨏G쉻(` cH$T}荈/CՒT6O]s;ӉGY۟K|6^Ĺn׿>մQ&~NGt&T"}CΓ,VQFKMy,0" a OlP%B›OCu )ACC-$ٰ{uqtΑw6u49n,RyW0,/ʾ*1_ӶßvThC ~u]8OTsZ טּ,' ;ܳN li(=I*:hVM9Q},J+ '?w=Ϩ9բzkQ8+[¾aVB;?DK?E H`DXz:Rzu]4//}"RAbwR6ꁎY\ Ybz {ɮ2sz:Uwц)7jCW#G/rݸWfr?s^q>X~Lһa|Wy{NT>&@*d{@*LY\(ܼ(;Po/Xh)5˦7Jx5v (|ҰP۫GmmF=Gdk>vZ ſ z4ڄE@wW ~@ծ0^CȌ@%<(ï IIWM$WoaPNmI;_͊';di=}_>SIc80O3B丁:``P:oV#?sdMr7*nbc҆Lz[\\/e#J>@I粣+ɮ-Ȅ}((o߿&gڵdm #"jN*"IY㒌:W2ic\{)c9v!Fۂ^٬nI:50d"ϝ)C}NX`K*[^@.1ҌXLhO;;Pt^FIta e%JfeGI&4[-a R) bz|An^.5prEJ3]9V<OB}=(` ʜ~{U& ,W My(H:>a z8Lv2T`NT(X̢`Z2kԂk݀Q}+FHiZ7K_ûtDp/oh9S!Rx_k7#~XXTO585A?uS1|j y x&"@/ 2A#bap@C`Y!DucAXb-R+Cw͏6yU u;1P։=@o$?I e$=Mtu^<J.}э;9w_?7*Hq%*rvߊ:ș9e3]7"QiwZ&f([RXЈF܃ .V<{ fC̢D\rl8f@{"usHD_e t#&0H쳜, +)yۼ2ݎʗR0l ݧcSkZY;Pcdqad=uJԂ=O&ށI4ťW9P;mnۭouM|;p`0q[YCz\ _g +r>lkJQM%%bNMgjrIjYcB٦KԭUs榥:+KeSJkɫX b> `b)#FE/ec%N)i%qj[W/ntr6=jQFΨ'Ie%īX{4RL&O1G9U)A7([p@ů_Ll0b@Z;Z7 &[Ds3uU{K8g% 8>`A֎ ƌl@."ቷ/p/ۭZb1Jٚ%iy@J JNA7cX}%4xNB5y[oز>xTz8.qMʲJ0nWw4HL&͕VP+-2<g^ @dz2Ʉ 8nji>Z0M-lxW9z$H)rzB1 +3Vj:b{7F1ߺMLM,b9CYف_ɰ;d(V/B.%uU7=T(Kgq157I=ûDc|լ8MϓNSoJVBf&ǫg 3gՌ<$uVsT~vPǜ93?9n3Vzz; (hNqk"%*T]䦢m#J+ك2hp @xsa Dļ͚G<ݽ h$-}ĘHaۖThy7#u#\TDآE%h?un|aK# s6dpI1sj.WS~ O% (~\q!|+ ڲ8(06nܿ*4^^R\.;ExP8kX:Lr_snKsܦNW zT}vpJ>G|Px dPHqaK㮍LiF:|j(5r͙9iWri^p? Rdr3kt.I=ڦ{i sy5)ޱB]3`֙W9gǟ 92?4]v[0r9!V̢g!/n?e`^f'W]@΁q$%y"ӳ0s^I(Y F&,YuyjZexmGS;6w@nSb?RrEOdNt\,o >{Ҍ Q AX,QӌHRiFbiT?3MEp3 .yVzU%;K_+뼦%t:J; `)7ςY. +`=4NB8&Pl!eI5{0V8\6V>UBwx$lp}#G> PO0I,Z ufpޝ*/qe1YTS$&XM WPr1ulWR@~CaKDlJW䦸٢`ϣOGѨapJH70'$λLUa"ŒLިƺ ދ"S<1C½ȣå-#? vXй%"x ©v# _RSHPj<6#6JpeG+…ٙJq0@dÓy1$x1|LbʪA k:IYct%xxmF!x0%!8kՉt,w ~V38QjS/WG,!)ApH|eŠ'Jw䈶^np3ڃ4l5k ˑџ#daރa(Rwk)ye!@3=3ϟ}oZh.&xn[,s{q:_rW2\,FIȈzsiօPR)P5łʅ:QCN[w0MɎ9l\By -~ bN~M] Q N(ew s׏bMHErt2=WsVm=MBYA ӖetX3TSҐPC.$uйpq/StES0|'0a?<.ݰ4fO1[e6p)X*j6cQ*nT6>K@8宅Q\w3n-F|(Zdg |x|O*/~|C.P0@آ[-)w]Ӟd>5XBz9࡝gyo%|=-{pCw1+ 2\~C/xn hI' :hTjc_H=t連Q벃({t){aeLKl)7n"jqֻU yt|+m P;_Gei_dV(n Cԏt:퍄xRt\K f)6u|h] s'$>FL3?Sxzծ6A][.O Oe5oH%旫ms]pҜ9^s#xth2?[EJp[y{o׶ש(hBZ쾁@t,9FHKY0%Ϡ$L&ѤKF)'y'\~rNXb5IsyCɏ ]9`Uh/% T7sɞ_qep~9,pe lTĴfz"9xoD7S}RCsFyBf76<@"מ(DѯӚ3sètw& p՗ʔfw5 poО!_Mr;OiZ Ә\|L`KUbm蚑pb3t"5)ԌS"F\@+LWN%)Ht(I?/z{UY+ឰ$֖U<-ҽtQR(rB؀zX0kzV'PB8n% ׉ {hJ}RUWYWG~{RA؅гW']r@Ι_o6 4 7:aj{C~F"xl10Vy겙y{gd&Pؤ-5)UmpWS]G*S !_zL%1: o{No\Bo@Őܯ{Kt*%,cK^ f)x2`-j}Sh L Tj1*ƪmfr&ES;E!lV/R`?k^μf߂2XB/0*cra켔.AArG9 Q\f|$ؗbFM~_eH?gl yj~׭ӒYw]uu {8+"hH!J1G06y .|%rSZ5xntYd)@˲o!ز6J>p7fV+4L`Bd>?B {&5݁[ps?#Khlc.zdx^ѱM1Q㏻l%2ը |"á..5!/`i=B=ߤ0UA؝6vT' Z{_Ykp5!KT/B.x|1ԃ:y;~T;Emh$VChIIA ˔#M&H\NP6%8AK.Jٕ !CVD֫+;ؕACk Lxto3vIr=9]H{D`yG&gVPÂ1ظ/ ELmE2 !Ԅ Oj9_bIF_U`o SI`Z :&@3\#jLB'6:`?u޿(A-rU|F]D5RL"s`ؐuzo'&nUBӝ8c 10gki~{AoӜxPHGBs|@F$͡04FG6 1D8eXY.M F x57/1g3uptWy_[  :5h_S j֡sڔNΡZ05wnԈ,zBqci]J IE2Ը8 dTtL}#(hJfSDxJΓ)RڰrS@$o|FMj?pX#rOܷƹ{OY޷圓sgp~_(1(U SBD(^5%[6+]\Rk`MU_cC$\1`GDSi(&!U@$gWSQ;XGݑӃZ& PٶD0](%ka#с܆G$B9Bc fWC.#[:ʎ;F-H$Aim,1;>XsPxs_oTK;Lmư7?p$& `|Șqή ƁT? -SUu45n_k53ˈS%֙_sZj5K:Һ,ʘv5ʦ[3{z[@X׃YyY $Q_ 3h$>ʓIL[Q;8&ÑMk,{# D嘱qi{Blf"pKXu1co)$̙Fn􌦯DpU%Smq]R*ݖpm~NXGs_8mhy;#Jxe^a/kb~?^ZDad2S1lKsz\Cf,D]Vb[AQ<+?G`H4֡ܜB$շ c6Z"OfVk-Fl¶r:|q =#c4~:Ӹ7Q3M^ l5VZ.7sBJ1XJ]3S}1 s4)1jF͑w!bq.pFzTn:{;1w ƧV(X w484X+ӧ#RᝳX?v<-R|kvqwSnVy#O?jY+nf'/w6ߝMgP5EQ9wfY"22@=rK[IʪpKrH#2(oifF!iOgԩq4Yf4 6Rj\Ku3\!B-&j"̰D1‰+qRCeDsuܐV?~?G f bJI^eV6`klKd,sLrG\r55+8d (*H9N(h7XBԗH#kV*.47(r"a{qZDϒ27y/j 9C3!Y蠖8סzM=s~6# gLJnFUT\xŊͧ  +;i$.Aآ?69s_CFFFy"ąZ HyPHxX ^Kа'P-{ңׄ 6.vŮ6!+߯R㎗#:@OP+k oBcDxsm`a&WuaI&S84*'q/˿RpQ'p`m:[U.f("5ŖWjM<4o4 bw=(}/gr>`Z:\%gGxu'`mM Oq:8~q|Q)pl ުsZ-*}ORaAroNZ0;-] [Ɔgh6v=L^@|BV'}p֐?-顿V5k"dAT@R`(M|vZ7xѦe4$_MX;o+ Ioj~@=Uh]CO>fiN):1x26,.zۀĺLW<+M4؜`\WǬH_Wl:i¿uOhv9L<<.oI otw0-(ɑ u lT4_Njl*~fFy"2%w!n["c1 @,fqbۇ=gJVq=uQ^2 LT ;J' ZT<-(DY3W8'Uf&yEK٧ՉE+mt(8v_RHؽ8H&B0?0ѶԯΞ ,')jU6Rnb6ؘP)UwlE5`Sm}|ܜ- \mѸpB ; ̽Z5E\ T" .gD7b1X!xl^)$j`Y}k8!)BV.q"=P; Zf5-J$#IkhfoTOVG+Mx:u:ݸK$3AW#jǁHPd]N~}bTg͎!@nrՏ/]+5U-eB-ǫ<ۦ+U}ѦSRU(J/ɕrB0"A)o1i5w{m[w3Ħ#R?!>/1猠r%V'v ox,qwB rĈWy uT+'UPCTq qSΥl$7WE@#)&9^)Ma ;.o8=]k\x^-h$%[[xx$,'bgպKZmg Rפ/aAJnuRCv=~. ,$JA+~S]:,5o cpFTyzS:0444| MTĭ\h{FzM[#x#G _u$//#;0̣?}}׺) IPh”> MY A ȞjGxQ[,bx+ {P5&IwrI^jŵ!$/4o 8JgL0{S_rU~NB*1UV"ӝyJTCǺez7cYTa%O2ޞ4Kwyu45q|qBT Qvްwc?}9SQ >hwFy<6Zpڼ/ˡc`y2SLOvRοUVY}Z`((n[5U'N; ¥M]}xt4Y<H^ 5 b⑦qfxAYߊ@c%Č1DCrܜ_Uhf46SB\g PPZk8鹻0&zehB.ބ|H0+N;WXısg;AپLcTZvg = UG c%+0F2e+ ZrddxҌ Bxg`ߚPj28 >H(xD0߱W}}5Őf8- 6l%=U\;\$'Fg:֫xm"\A` =Ng+} R ZԒ(imV*k_NžTE8ovEz*+ؗgKTgeu;˨FHi?08g$9(b[naTZ^s6Dy`y}%=e8GqU*ˈF$2իuba#y̕gDo2?'46g0Z_rh-B<1ij1)7F.>! i$,f/΁pEs ܮwi:HXL&0SVqDWڙR'Q*oC.GQ;xw:hrg?9%"sVΕQ|ɥ4a+JA0mՇ Хu-(=Ta*3dŷEo= ({n6!vJ`.- kS˥DXQ5*zC 6N6[A쒳ק^aRK˰Khϝ'E;$Z>ͧB|$LD1ph2/[i*HԊ`HzSޣw!:V em fRfO?ܹؔ9ݘBE yyW's?+i*TPoE=}:d'"Tvc4G ^'nxk|\HE4ta TҘ98m|EsŬ!-|" "dw4nH)v,RW1ݫuD ]ٗ+q̚F}=l(g_v HE7ίe"uQEg| ,̨0i 7/O&Ah*m',m#u&y"ݹqD@b N1@F⠎QB3Vq:ZJۏ8;}xH<̚A%`MϷѨ\Rt3Yo~ݳ6 Td4釭G<ж4ߤC iv1w(E--4Xy5=m+|mrrk?X T5CK0qN=kU|)$eߢ[ÂDŒ;M+ie ǤlRa+7r↢h٣ɓ ٳF Q'=+:IZ@]{;tV<1 ŷ]=Cl1 |o+q~Hee,3ϣ}͞/W "1c$ eS:PF]FS&#&g]V e,$~CR苮LˇkFO/ b/f˥8?a7eBo䧷;{]\l7^~T U%(rWqgs!'i%$Fwc9(/a#}ry7:ZYrl*_+9tE(BE5;}J>Dip]k '-F/uC`\#.JU}ig^6Ŝ*H3 ֧RK:l $i\aUOo`|1ZefdE/FbWg#J9hMrEN$4oD9_&)Q͊1*mgJBDA>9jg2vd V/]l-Mk3탕=*?:(97F 3e.gGIS>5 ]MZPBaԴm/GϢ79}li1T5X{iy0'H.y-bUAH-M79MTG|; iyS{gS!/'RL:t +}QRb?*Lޥ!=Cmu m5:H-p@I;2Ĺe56EB کѿ bߑ h .ҎPٕ7ݬDݐzJ_g`SI]#3ӛH]@i\1˯=1DFk76G8Stc$vl m ]#`F:yX`9|:-=Х4~*)iay`KY\T_G[fo x[]6>4X\7iLWj^&joBKo& hMQ'ݳ$ixU*k!O*=C+u"BS?P&U 梭ĥX.~qĉ!˙<&u0I5 u--2*.G`h0 N[T\%I<6꼵./ڠzY9D\NJc(#dv=;|/XN&%캔&(,>1-˸89hG%^PAA4N?P@q9t=/2h!_\Qmk )>%~7ڌ'}Ozqpby[0 rRpWw6:.c3T%KdLUZǮnQtjhѡ!AyßaKkl_LeE'A:UCހc*[v "~'Fc .ŇrNly | š̀H_ xcʌcp>ς>Ba?#yջ?H2; # ^3ɮ3ٵ&ݭw 8k0Ɨv~,@!V\U2SԼ9?G"\ܤPBq$t[(ǹqh:ګ^񘱢mP .mq^ƫR ~!-}FcH#xw׆x]-z~DZG19-S:NLB֮ GQV_EF*XI+(ڋeDbBnDg9DgsͫlZ{ QZM?c'=lLkANAX?7?G3;:߈.ddzTZEg,wt.$[;YI!G4l|7ĚB>αL pzeٻ^( C]SkjGKkd>ς0I^Ywo-H!SԶ2/mor.ip4==.D+GU_1j+*]5_,Vj!6A$AI==tCe4I:9T.J@[1S]#$MF)UjLĈL5O-'DT4N60ϸ}׊ lq_zYN0lxUxڼ:3(Go}VF\oG!$ɔ'\u^ *^%mhg;t͜KrV`2HfECthe"}%/[Qݧ@Mz){p/fB= "]GZlc܆C*qpE U)wcG"—rual Ӛ Lz@1fj#v-`#y*5%Bp.dr? yL׈`G2$0mlP Z#䙞j +LX?!rk,beXIGx-WnLh~/%JDLXQi{Jb%=V3'nB|ӕAF;wl9mE CϸBF )#=p.jd ;6fTiY$mbC?יDR>f)oV㥗929`>ن?=3˜Kp)S*Ilb_O2nVT4}0E#=IK#=N&iQo5p<x^i} jHzzp`w@|S8tva胬;qpU23OܕWzq&GG2! UT&xARjp1ø2rƼ*j Q22\Sfv!0;@,ٷ{n!/[@FaR'&@LN='cv&(A4&xR{m7Y">@dWskC(Tfqb=Wڇ%Y j+C־VyYQ,MFMFC> t(=_\3*hd"%c?[0ū~ipݢdQHДBy>zZ*)M׈[fF8U`8`׿R \4u} t)霥_^y:ӻ7 b'MNS-U6:[}cP<ժ <T#b;֪J؝nŠkoX5Z ~"89|82<[6T{-~ oz:<^mB)\p +'}vZR^ݳN)`Y&z,1)lUI0I얍_:*=S. L$|]7cIBO]?ZŔr3f3)* aUjNь3T}8r@ -b>~-8wMOHER])}?,wTSXdV<%oB;jmǐ 1gKa]l2o-<&XzYG{:$mz#_xXYS? %8\ddyhK M S\%VK(EֹYܝ/(ʚtEwa@:ěV x'w=%ɵ50 J}EyVW$t@0jA) E=nϠ8&mT"6J}sd\@4f=7 dγg?~S2uCKX B/7sgZZ1ЏRNt0:DD,nʈt8(b?(kacl Sy4u?6^JPF(XdvY4/Y*1H`u*OMJ-?>j,%Lפ=YWD3VIqZT퐮~R\2~l(TS?ORu#zXJ= T~t}2 |yNJ?{#!fD,+2 Ԉb|a.%#ϥ o$>n]I!#B8́ fJ! }#159j$`гT_OD>ʼ\fnAtƧ'ZWH 6j",}'TAB09nGTSq0Q_kozÉa!ox<-T;f<z^V,!%7]a|S"D[fql/OKTs,0RxT|@ά7Vʃ61[&î,ߝJKPnc ۏIK˛Y 5磨%B0te|BGuZڃĬL$uszo]d`>@a[a@ 5= 1"]X}kPѱ<-GA3!/ך?lN,`"pW 6lV&?r\T("! 1qiaAۣb&9 s# [C=أYoW[bvJuL‘NSrυ&t϶9E#+6چBD.$RFoS㟂J_2>_IFPq}ourD L~Gڛ""gyMPfկ `lGov`gMyϐv9>u/*mRV^; 7`eC[I#{$c lFL1 W9:X3'".@3d]qaBq\rܗbeKԲ":*ѳ<0NY>aU6>ᣔ,IihV.9>%aUr[v{8Gy ND:YbǛz=&U_~FN!1'ֹ # c a:Bj/uމ= '{@YK66BGoVe#ưo;OFԚ[zZQ*5M>d; f`V~(gҐ2UP87?8jK։*BZ0RGlMc%#明''(4NϬh6c5g``MxK Kꝯ^apL ]IEA,B}:ua]2aoi߭M%d 0 {`?[D?|e ml#|yu7*A26мG܈†iȰ}|cZ@ʪJ fηtuJ! G*1}~:/{ C/1 X wt /J-g9-'`qWҔi6bFjUʋԣ=]uNe ($h:q)Տ" ̧7=`zz-Y-obCV7,zhL+ ݺvdT ˺\n?guF,xߟ<$P2p;rMõإsMLB~ig!B?S?k*Kkx5{JMj2SyQ`ZrqAѼ(~}dK}ɼ6ʍҀKf=vCI[@O!tu~<ྑHNq8k^sZ,Y\p@k2L23` ]He^եEq C?KCwEǤ۳=LSL^,i=H}7!:2'{S@u+X1, 6ܾD ,80J ϋq~Jw8L߱12҈)0.( Pm4j.;p|ͪ RsLV攵-%kR[ cцPڤґ=EɅc 78UsoiW\[!}KxYj)wܪ'{́@+$m_3I=vx_|b2q?mAca 8!PDÝÌlV[Y~M򮮉&/*`9n1JL[KfzQQϓUkNB?9OyRp攻\Ê[ ݠGU>PSգ[oi, Xuf4iPCe͛dȐg' }O vU;:3Bu*x|ˆ, 1q̣uwe!"dǞ'iWROD&ZjؖӲ``հ>|*mA' o|wR:\cqY|^,Rgm>#F!$04^}՗Iȼp9c'T*:4L;gYyʥh?>V镾SCA _!r˘ C.9 ɐ5o"I/qn ^ޚ9El@rO싋Yw0rx%O56RWΟcsu״8V[@:L⦅ƳbSiݶ^w٠N79`$u~+?V<K_lY-8{!vqEF!=Iװ̐tYʋCg &8*,7# ]',E<0 A딮)AxHJat&'ZM.SO]y. bq *#K_-s(K)`Ql̹Z GӢSzOQe" $,y JzxtF<I6JΣÈZSpg<߃w`ž|*luTvh~LဠFfP#U@K|^V(L͗^\Y-yDq': {{çQFr.FcC)|؍<댝cgS fNJ΋jm|#\#FѕjMd%;~PtY\u}KCksi}1?E~fo(EOX}Qc{=\v /ĜԂD_M*LqbL&i\iug=l %]?{Ccd#IA$2(rG9F=Va#7UMUPHAQg#}I@+k#n ,[]+4:ՃQmg`2MXn KWf.9o}(}{_nےZT0-B"[ݰA.a9ک~ 2WPR.yٱ?2q/՛sn >JN gci YF I]ne]!m.268`H\q[ ֌\R iChDawt7XZF:dO׹{(AdcGY9{fIibTBX2nYwIQi<ǹLY7Nrq#Ye~oHWFD1O'Æ4ӸmjFYؐܞ. -bCܬS|:ODmB1A+{X)%ClkX@UFefQº#O%CNme iWawC\&Rުط)!UL~ϮrSNƧqSyQA 9vuKo-hZjO[FQ-I1< Vy.~zeq*<-ߥ€w6_Udhr1T@20?oo;kTxG0p-. ~KprLc&<]jn jzRF 5#' vnrxö\.g .f Y"sB*YYbW }zgڌ|w.4F󕊆㌀uǒ6,2+[EzC9in4_ЮtܹCK`A#}4":fk$Y)V 2SEى&p_,#F#aTkmEחlC_0 pT].Z~r\]?O1=26q4ϻ0)u]ͨKUkz@HOg"ˎ 1ڛ^URlJO-yⳀlRߛԻq Nj*FanZ7-cɡϟ?R`|UֳYJ+{ٞwe{}P܌ۡd^4,DYY.&<_ͯ$[N^%>?G=C]^nMX=K*ĥ)g%öJ" /qqЛg.>[I ;lv[w˨+tkKSL|Ji%-= 00PT:YH!YiUd0(CbT)j$ґK!4g^Ȅ|RBuAe@ڠ-M#qWL3}?C3XRh13=H. YS5߇Updԧ* 7,(XEhZ@K'w\@Hi<[/f^UUΘ=3.AZ.(&oڏ c"UJ8KYՐ|YC/rSAH)ɔDMKNv(,tjCQdlHSLh`dGeHCp-n[8)rE?+>a7@_V,><sh+28;>J_ީN#2?Tٶv&,1<OcQEOg :~cpƎ*kr(@4q^t(sfD\!e=9 PƷU?l2E# {$we=l҅l/j577pã#D*45zכT07o8. aNf^C5sbp2 T Sghd .Aэm#m2'Uݟ Cj)yy50fTM&pID2$*x~ktqPc:l矷#zW<7amԇKD^(8 \O.dt[-4 QIatW8ƼI9߫=OLi#xvK!hUl*h?> /{{*7\zz{&}q.j|[Ո0!b;fڌ|ǣ=8}Q`-6Tkk;QHI&*t7j]Tzel;-jW7 [NίHֻV.>gbO) ;b;r냺h fq1NtݬH)޿a9`{>La1 ;N;T%^ۛU/a?Sz#rCOƅ&?Gȧwk=-%']^~ը׌CD"\_ yJ2: /y1mr~:6(Yh'}Lx'48Lr.Y),*MVQ{!|3ah!~ I X~d>SK`eټYӮKnDMCzb5YX*S59RZ<| $#?=C7@c^3yl5}nH9pX+$uDGZ]햙#9yM߫yNTj!%8bCj?8Wɞ@3k,s&]AvEm"SlqadHM / rHQqjLRȪPN44"LQ7hgN0mNS8Ȕ >̠ X( E^kS4 i^:4Eb´0ڶG ?vg[ G Eu:Tjȩ]jۋ+)52ksd. ,{B}_6& =e6&_#HS]%®g\|ɛOW<H#yK(rSuV1$(r8Ӥ8es.^N˶+E Q5ą:x:jd_h{h :݆TECt?w/Pܸ6}FYQlq*&jW7ѲX/b%Xe':%9w}8lJVCR&[2Qd希?/䉉e}$kӦsɚ_&y灋l:M P4[?3{7n }$I:l=FmP}wsW}Rs fz^!u 3)yOvڷT14.e*JG `^&̄>M}\5c><:J%'6y_Aq78nj:@ClI'%gsM m l>׺@=k#eS}uC8nfOPҙ4v2We1uȗtIIym[p~S1;R@ϯݨႇ3$N >ڶpLSd•bi0XWb Ӑ˺Fs43q3qp AV~1.!+{ ?f QiӪ<5EcЈڦ? ?S3[( u& yLyẠ/Ia:=ƍP7Bi8b.g#>8 e8m?/rBA]#Pl5%CQ^c׺F-<E-/h8Ѩtv.bh]j;Z~Aq4NgU+4wQZ]@& Z#헣EFkjg Kxȃ#rX8R׌ǡU`oXp5SEDx5{蘤2 Hd"6'eY`lſnCíЯp+,&&QBLՔ͌{6{viv]-0=FYEa˫3ŽܔLzZv/JXɽ|Ie>hټ8Pq[AHg(T0֥ ̐O>"({(pAA:OҚui½!JYΜ7רmڿ[@?4#9;Vֿ GG{@ԑNq %3=.džP;VR]{8=&?3<֤[m (ś]衝^Le s6I@oI@uIskA2PRh3p}lg}ͯ푚Xοy z YZ