sssd-kcm-2.9.4-1.el8 >  H   ,0eQ= U]9Z5@ 19Pf,$2.Xy BdjD_=Jy'%{k};jm ?f`?$pk-$~:j7ZauS) 0 . D1!6oVf oQqZ*Z zAI }i0{q!=ts"n ;[& Ecrgo8Ɇ:6x/* *4zKF0_ ۼ wϕ9iZ?:\d|3gXQdfjy좭l'v/©Q4a|ҷᡙCcki{ J Q@ ^u`7di/*?2[s:OeFcśc~rps7- [84Ӑ Ie5e046c752aa1339c383ea1df764d0ebc42cf53ebe45acdc6c9fd3e5c048903c5812ee24d94c4fd2e9720e3ad18e690c87dc5ac70302047c435bb500683066023100ff7815de4f1cbd2a8ba2533f2edb404905003f3b9efbb9209939f8d809ff18c9392c2e276a2d42e15b63a0e7093ab053023100fad8d847bdfec0c0674438c23f25fd3bff8ca87741e9e1982e57e0d588e5e417f3e2fbacb09153f962d605dd0708f6d50302047c435bb500673065023013d4ffcf6156af9e870c94fa7a9a8cbaa94b4439cf22e1a712d14bda12b776088e2665f848b8451872b3e18663cc78b1023100a98ad673841571f1ed96df55ea1e50e078c4f01180a004d8d788d857862eb413726413735866c198a3aa8a6e5de217150302047c435bb500673065023013d4ffcf6156af9e870c94fa7a9a8cbaa94b4439cf22e1a712d14bda12b776088e2665f848b8451872b3e18663cc78b1023100a98ad673841571f1ed96df55ea1e50e078c4f01180a004d8d788d857862eb413726413735866c198a3aa8a6e5de217150302047c435bb500673065023013d4ffcf6156af9e870c94fa7a9a8cbaa94b4439cf22e1a712d14bda12b776088e2665f848b8451872b3e18663cc78b1023100a98ad673841571f1ed96df55ea1e50e078c4f01180a004d8d788d857862eb413726413735866c198a3aa8a6e5de217150302047c435bb500673065023072fec64dfbc22616409e2ffca9b63cab9a279a7d5f01759148b6a19e61b3e7be5b702600e7ff2e068581127e9dd70bee023100f4d5790d8f9fafcc16e5e84ad3495d6a6f9c877b272d97187d7ce9bc2f7cfef8ecf61fa760d6383cde0402690f0f82ff0302047c435bb50066306402305afc06a013e76a09ebfc71ed79db46f0b57ab6a6425a4cd1f347caf9d04c223242cccc03b6f8457710e62a9c4bbdf4f502303101bf1e1f7bb17402a754198504f6e489675734815ca63b163499299dd231990e0c7bcb0fab517d1c3088366d5e971a0302047c435bb50067306502300f4436321287982e82cd72cfaa40346b3ad740c82462a845273ac3f52052343b1c041eb7f2fd391cbdcf1b7623a9450f023100dc521d52049b070ee94ce81fb42e5b7b395dabc0cbf3dc392962f9ab851a395fb3ebfeb0e23bc33e2efb6cb2f394e27f0302047c435bb50067306502304eaab9089c2477b11293a1f3055c1dc5beedb2e7666fe9a77fa0aada69be072af755853f38db66d1c95e8b519b341704023100ec3ad8a1335850eacf4dd59fee1263e2b98f8e14fafef4a98360bfe6deddb8d654e431d1fc4d38d9167b556886d356a50302047c435bb5006730650230440689fc965fcf0268c318dadf6b7ce495e89647634d34b084929b3c85ab0b393ccd0b2f2a54c02647232e35cc7f64b1023100d1cef12ef88a96e5691dc1ce5dc7519674d7dcbb40a9d0ac672d00b1c9865d03060a1e7f1a9792b730b08ac3dd9250f40302047c435bb500673065023100d4edfdc40b6db9fdac67d70a9accca9f2ff59bc23bbe6118762f9b5bdfbfbbeae348fb7b52b9ef2abf7c99d60a0a3dfb02303fa6f708c51dba4a2548284d7973e7ebd9eecd20af212735b0616732f3ac06261afcaf5946f295539a884855dbfce6450302047c435bb50066306402300a402246df6884547e9e461fe5624c3534c161da168f53a9094a786afbd0baaab50faaef5fcdf34ff75abee9e7bf11760230015bdbdf561c3c886849f3a66c052dc9ef4eb751a4ce02641494bea2f07ccc32728cac9077c5b3a01f24d409cf7acb5c0302047c435bb500673065023013d4ffcf6156af9e870c94fa7a9a8cbaa94b4439cf22e1a712d14bda12b776088e2665f848b8451872b3e18663cc78b1023100a98ad673841571f1ed96df55ea1e50e078c4f01180a004d8d788d857862eb413726413735866c198a3aa8a6e5de217150302047c435bb500683066023100ff7815de4f1cbd2a8ba2533f2edb404905003f3b9efbb9209939f8d809ff18c9392c2e276a2d42e15b63a0e7093ab053023100fad8d847bdfec0c0674438c23f25fd3bff8ca87741e9e1982e57e0d588e5e417f3e2fbacb09153f962d605dd0708f6d5 ܉eQ< U]eES=QLcq?]Ar>͋fUQ#-dp 9#94]8qSDQRP\5[tMeÅ>WKg+~@G BWY YFQ_ v΢@A2AhBKf+3TGLet<6fUy8LgGBVk~S/{[>FLe>ړV#p73ۨ~t]-xbf ;MtPL.`/BW45]e={$ڼ1}'CxV+=mNV%3}by Xln:KW[VGeA-ٿoӍ0jT/gv\r^(ep40Ʊ$%aRgZ8ѭQDZR^h*}CITO?YrW)#ى`h/'nv]įg8srp1?@>`B4?$d   B 9?F[l         U     >X ==h=(89:h>U?]@eGp H I XY\ ]P ^ bdVe[f^l`tx u vw x y0 Csssd-kcm2.9.41.el8An implementation of a Kerberos KCM serverAn implementation of a Kerberos KCM server. Use this package if you want to use the KCM: Kerberos credentials cache.ex86-04.stream.rdu2.redhat.comCentOSCentOSGPLv3+builder@centos.orgApplications/Systemhttps://github.com/SSSD/sssdlinuxx86_64 if [ $1 -eq 1 ] ; then # Initial installation systemctl --no-reload preset sssd-kcm.socket &>/dev/null || : fi if [ $1 -eq 0 ] ; then # Package removal, not upgrade systemctl --no-reload disable --now sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.service &>/dev/null || : fi% ځAA큤A큤e_eeee_e_eaeVeVeVeVe[e[acfc8b31ea1b1931377b6c6c0f3541e0617be0a9e24769d5e1f32689120c0d6bbbac31b33f419589e342f20381138c0dea737fa71b0d67a0db97020b4451afd8c2f6ae53e988971d19b13a2104ead7d8f059bf8e7097a1a5d82ccb81764fd4795f2aade36c9fd46eeabc04a117baf50ecd838b849adbe7537157efda814807961081c323036e6ace67aa6a6b38a9ab880e21f78ed43aed9e43f35af6b71436194d94bbf0962331213983126a4a317451ab509e370808796bee50152ccd8be2ac778968879f9fdf21c8370466fc0af46d849ce85f34afcc834f08723a9e6b4c547719a225a0b16557590ec7420d0f56746119e9a8c094fcc44eb1e0970376f789acfc8b31ea1b1931377b6c6c0f3541e0617be0a9e24769d5e1f32689120c0d6b../../../../usr/libexec/sssd/sssd_kcmrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.9.4-1.el8.src.rpmconfig(sssd-kcm)sssd-kcmsssd-kcm(x86-64)  @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @/bin/sh/bin/sh/bin/shconfig(sssd-kcm)krb5-libslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.28)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.2.5)(64bit)libini_config.so.5()(64bit)libk5crypto.so.3()(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_iface.so()(64bit)libsss_sbus.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libsystemd.so.0(LIBSYSTEMD_209)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.15.0)(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libunistring.so.2()(64bit)libuuid.so.1()(64bit)libuuid.so.1(UUID_1.0)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssd-commonsystemdsystemdsystemd2.9.4-1.el81.18.2-113.0.4-14.6.0-14.0-15.2-12.9.4-1.el84.14.3e{@eReRd@dd@du@doMdbc&@cR@c|c_cc@bbγba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.9.4-1Alexey Tikhonov - 2.9.3-2Alexey Tikhonov - 2.9.3-1Alexey Tikhonov - 2.9.2-1Alexey Tikhonov - 2.9.1-2Alexey Tikhonov - 2.9.1-1Alexey Tikhonov - 2.9.0-4Alexey Tikhonov - 2.9.0-3Alexey Tikhonov - 2.9.0-1Alexey Tikhonov - 2.8.2-2Alexey Tikhonov - 2.8.2-1Alexey Tikhonov - 2.8.1-1Alexey Tikhonov - 2.7.3-5Alexey Tikhonov - 2.7.3-4Alexey Tikhonov - 2.7.3-3Alexey Tikhonov - 2.7.3-2Alexey Tikhonov - 2.7.3-1Alexey Tikhonov - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-1680 - auto_private_groups does not create cache in IPA server SSSD cache - Resolves: RHEL-10092 - logfile rotation for sssd_kcm not working properly, sssd_kcm never receives a 'kill -HUP' - Resolves: RHEL-17495 - New sssd.conf seems not to be backwards compatible (wrt SmartCard auth of local users using 'files provider') - Resolves: RHEL-18431 - Excessive logging to sssd_nss and sssd_be in multi-domain AD forest - Resolves: RHEL-5033 - Incorrect IdM product name in man sssd.conf - Resolves: RHEL-15368 - SSSD GPO lacks group resolution on hosts [rhel-8] - Resolves: RHEL-10721 - very bad performance when requesting service tickets - Resolves: RHEL-19011 - Invalid handling groups from child domain - Resolves: RHEL-19949 - latest sssd breaks logging in via XDMCP for LDAP/Kerberos users [rhel-8]- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-14070 - sssd-2.9.2-1.el8 breaks smart card authentication - Resolves: RHEL-3665 - Unexplainable error "Unable to find primary gid [2]: No such file or directory" when SSSD performs lookup for an AD user- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: rhbz#2226021 - dbus and crond getting terminated with SIGBUS in sss_client code - Resolves: rhbz#2237253 - SSSD runs multiples lookup search for each NFS request (SBUS req chaining stopped working in sssd-2.7)- Resolves: rhbz#2149241 - [sssd] SSSD enters failed state after heavy load in the system- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2196521 - [RHEL8] sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy - Resolves: rhbz#2195919 - sssd-be tends to run out of system resources, hitting the maximum number of open files - Resolves: rhbz#2192708 - [RHEL8] [sssd] User lookup on IPA client fails with 's2n get_fqlist request failed' - Resolves: rhbz#2139467 - [RHEL8] sssd attempts LDAP password modify extended op after BIND failure - Resolves: rhbz#2054825 - sssd_be segfault at 0 ip 00007f16b5fcab7e sp 00007fffc1cc0988 error 4 in libc-2.28.so[7f16b5e72000+1bc000] - Resolves: rhbz#2189583 - [sssd] RHEL 8.9 Tier 0 Localization - Resolves: rhbz#2170720 - [RHEL8] When adding attributes in sssd.conf that we have already, the cross-forest query just stop working - Resolves: rhbz#2096183 - BE_REQ_USER_AND_GROUP LDAP search filter can inadvertently catch multiple overrides - Resolves: rhbz#2151450 - [RHEL8] SSSD missing group membership when evaluating GPO policy with 'auto_private_groups = true'- Related: rhbz#2190417 - Rebase Samba to the latest 4.18.x release Rebuild against rebased Samba libs- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2101489 - [sssd] Auth fails if client cannot speak to forest root domain (ldap_sasl_interactive_bind_s failed) - Resolves: rhbz#2143925 - kinit switches KCM away from the newly issued ticket - Resolves: rhbz#2151403 - AD user is not found on IPA client after upgrading to RHEL8.7 - Resolves: rhbz#2164805 - man page entry should make clear that a nested group needs a name - Resolves: rhbz#2170484 - Unable to lookup AD user from child domain (or "make filtering of the domains more configurable") - Resolves: rhbz#2180981 - sss allows extraneous @ characters prefixed to username #- Resolves: rhbz#2149091 - Update to sssd-2.7.3-4.el8_7.1.x86_64 resulted in "Request to sssd failed. Device or resource busy"- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2136701 - Lower the severity of the log message for SSSD so that it is not shown at the default debug level. - Resolves: rhbz#2139760 - [sssd] RHEL 8.8 Tier 0 Localization - Resolves: rhbz#2139865 - Analyzer: Optimize and remove duplicate messages in verbose list - Resolves: rhbz#2142795 - SSSD: `sssctl analyze` command shouldn't require 'root' privileged - Resolves: rhbz#2144491 - UPN check cannot be disabled explicitly but requires krb5_validate = false' as a work-around - Resolves: rhbz#2150357 - Smart Card auth does not work with p11_uri (with-smartcard-required)- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2144581 - [RFE] provide dbus method to find users by attr - Resolves: rhbz#2144579 - sssd timezone issues sudonotafter - Resolves: rhbz#2144519 - [RFE] SSSD does not support to change the user’s password when option ldap_pwd_policy equals to shadow in sssd.conf file - Resolves: rhbz#2127822 - Cannot SSH with AD user to ipa-client (`krb5_validate` and `pac_check` settings conflict) - Resolves: rhbz#2111393 - authenticating against external IdP services okta (native app) with OAuth client secret failed- Related: rhbz#2132051 - Rebase Samba to the the latest 4.17.x release Rebuild against Samba rebase.- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8 - Resolves: rhbz#2119726 - sssctl analyze --logdir option requires sssd to be configured - Resolves: rhbz#2120669 - Incorrect request ID tracking from responder to backend- Resolves: rhbz#2116488 - virsh command will hang after the host run several auto test cases - Resolves: rhbz#2116486 - [regression] sssctl analyze fails to parse PAM related sssd logs - Resolves: rhbz#2116487 - cache_req_data_set_hybrid_lookup: cache_req_data should never be NULL- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2063016 - [sssd] RHEL 8.7 Tier 0 Localization- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/sh/bin/sh/bin/sh rusvuk2.9.4-1.el82.9.4-1.el82.9.4-1.el8 kcm_default_ccache.build-id8283d28dd4e44ba57a0d6b93783ed86c1e674026sssd-kcm.servicesssd-kcm.socketsssd_kcmsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcmkcm_default_ccache/etc/krb5.conf.d//usr/lib//usr/lib/.build-id//usr/lib/.build-id/82//usr/lib/systemd/system//usr/libexec/sssd//usr/share/man/man8//usr/share/man/ru/man8//usr/share/man/sv/man8//usr/share/man/uk/man8//usr/share//usr/share/sssd-kcm/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpioxz2x86_64-redhat-linux-gnuASCII textdirectoryELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 3.2.0, BuildID[sha1]=8283d28dd4e44ba57a0d6b93783ed86c1e674026, strippedtroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)0R-R)R3RRRRRR+R R RR R RR/R0RRRRR2R'RRRR R,RRRRR R!R#R"RR$R(R%R&RR.R*RR1RR7utf-81910aa5bb4b40ab47679636cd168547373c2983a27b5accd018f1f627a90574a?7zXZ !#,s] b2u Q{LXһj6 Ojgb^83C$ w؝3L\^lõ@IWqaݕnwGcr$,y3Fެak`6撓MʹZƗ2(uLÌs*$ezՄ/RT5tQR4^ߟbh $nqTi~3KZz.6!=vLVtu77G:c7) xcT\Me}JïmmY 1($T 6B_E !{)mƍ@LAwVZ*,A]m&.si1Q[XEmTwpng26Î8ԽvVЈ)<mo#8C 4*B]r/[ +JVUAoC}AsdWerm܂C!({7ϕOӰMYhmvaDAn-]J9[߀:f \'r]Okj&&K*Sp/_Q@3w :~$`zhYLn1YZiwdEvRkkȕ wC>M߃n[BB FbJVu#_PحgGװ^+|JQN1 :-QP[R`3$ '/$(w]Npy,rYfm 6Vum7oF w!څ9˿y8Pڷ %YP9rS:ގR9mU!yH pF ĺ^a$*g3z\ܝػ7T2~|ą  )ՐG k/a\g{|m:":ejJNuӠ>K{ᛙ[kH~ɑL=ؗ,CZеtË/-[ÛJXX; ?G=sY5Baձ l%k]0rFP~] ٚ;F|o{t>MdS~ED6!)VXO#"ն^lT@& ޕ]I>xtQK5즽`;)>aN/ARg**yMACȏ~5|No /Qt }̜@:n.o۶ ba7kL ,4q4A4KT6xֻGoכbbʭ[#`kK X;O"[ck}-Nĝ5.sw%2uo55\/ *7O@/v.g{xɝ~ǀt.0F³2_k]ېL\h6 Mɂ&Ov#qmޭ(-SLhML`3/aE9:7\MϺJ0s3)(jmL'2 :v5O^澋`涓De:vP,[ ]<ЬNv~;q ?p(:V3ֽ:`AjB'ǀP6̼" VT̄F[ڣQDe|!}\\0zZ r8; a yHq駛/GkRuzH{~Q$uZ!_?'[nB/ yi'm`5X;O?^`Dgȶz 0-|Kv€Ub ƽ{m4DZJ7{Xi%qʺO6іU hr%/ *ĉx'܉t̸7|9AN>-E6QKSݕdvUSi+: IUpݺ!F\D ޚK A3Iw@Kt45tݚsz%|A{'06!D2q<~9%Bՙa+`Rĉ?h7!MƖW׷ UHϤUHlh\lhٺ)0h]cu+ZBaLןMoUoUjb O|6_W F!/m4.+(أpB!wJ#9J#Ȝs64rSÂV;u@To ӛoR[SC'Iʟ!_BX,`RLk'{07Ri-,3{<;hjR,e uRJ 67p*ʮWrᄞBvx~+ 05G{P ѲTWud[JZ"nPhc)MzF/\r}élnECzA\}!9C$~k&dWF<&#)FI1i\;݊~{5Y8F=MPJO0%U٘F/ 3a9z]xsp+0_pn1#& ]5~Ev``-R0ev/Vbp=VPT͑ >KBwTU'W:i[v>m <{!a?4jǀ΀=9dۮ>PjAsZ1Ƙ%SkDfx 3-cwAEtddb,sY*K08۩TZqٻ-cs$-Sſg. h8LOK!{Nftd9IoK:(, Mˍ$&ASn/ V֍I@RАT'7Wa M(HL{Y 3d:@` HޠCQuξV Ӌ P;z|B<8 7T.*dK-ϫ2r#ְ֕wn ˅,Q2Zgc!2AW;Úe$X+W ;;o(ڝU-QEw(6HzvN@*jPzSԧTu z5&i7BzZU|+<0 hvϩWKO2FJ39I ;Xg} "}ZmUkI5<*xq?2RC\E'ނP*ʼn1Ҷv<}AgXMNX#jiW4tbq*l@b=%a xz@MNlG:,AR۞HX09W`i}(+GNՔV}.[و: lVd|Aؐw]^Jn0Ojr-/X/CTWw5_[ k6=`_Ҷ N SZABUEdUWMHlpJ+aTsWm{J1S}Ԇ >e{Ķ/򺐂|g[[4Pe4l:ʬ YmN6XfݏzcX/hwFo}ĚpQKК4mٶ2f [yzïd9(p<3&mz?c$|gT ]n>^T#(0oC3[<(JMᘓc \&ɭRU%̡|sky^ JZjz+k3)qmIT = c}X2zMDRmtڭhUd nFOg0@4B덣ށ3Ox72Q'F1o.<<a Ɛ tWV(PzXaƌF:ㄻ$-w\\7)0 kE|%"0諛uy.( ]mq)}ƙBz8jCfȨTeij q_'%4" 2!~cdMz b3mmm%it!XLj 7cuBAݔr w&\6MBuxa;pB82sEm2zC|jue^{Cyy ^(3`t]Q_@`HȏMpט4^e.G.+SiD6ʪY>:ͣ+̀rH$x/o71%hPk˜rC 0\60Xtp1'?*4e&0 .nk{.a#E&] ӦYfclؕ!0q~;;%\7>Έ;bivɰ=$1zS}J\d'h+"7d [ }%5ל-ݐЅ%7@-PN!XQwZ N h=to_EUҀ `ڿ@6CIa謵fJX'cPj 1r>M&IkOKfy[ ,/_5SQqߵx ",|A>t"9A{㓮AUn91s! >mʗDـ205rY~5LA|S -,(5>%"OM1>?b2-J0I,s``tLYx-७t=36 DŽcTB؎ON5rd+Rdx{(}N;o I7МL6 6d]fEg VHٻDf5|yzH1恛&d?bh Ŗ +5wT߶*͞mC WE ~R9R9Ơb9姧|YPh9䥫&`RF{5^A Roi6a[*;9gx6VJt)U }DH{ִ)5Ŧ312I^JW+?N<$jfȦ£+Rm*ڇwGM5wtpFGmt%ʚXT9(B ~AT 408(c/f)6L08@X7z ,[91OI~Uбg{7(A?j2Zh |&CTj). ж iǮbI;_遌:i^c0y;Pé\uu(2ӆ0#%rK&\x"gTg{b /OcU.rt7R{#h;`@IvBL ۯrLjNx=.b~V鵙`+O5Y'>u~ݣ dKb?.ѷ\*X`&{Fwo\HYfSvbo$CCaGiHT_W,V.NӞI(  $I#><GA3>=s:bZX)Xӊ'YN,B`y:F yPgusW]RV$X3+#*1Ė֜IҘ;OwLs{ۡccX}#~חY$;GиPj<n^Ua"L4n4?&_ 6E⫮/K,֌Q!7W-vUAsYj<$].mm-qU+MV|ԪY 7S-mk襆UJ!3"Z"5L=S A910[lp bX?8X u7" ddzbF ovsK>l<ɜD+&xɖTem*!)9!|hTvwpM1 c1YЭ Rhu@7u!k(0;箣[ ?YEr-VV-u(L,3D}8=IAK][!m ? &_j)"a:q?oF*߉=,IM5'b ~ҭu5 Ԗw}[詎+Q@\4A`peem 77tTYlB(46ix>5g39hCq2猊v2r{2b}Ԕ/G.xKg/).QJ834b600y-z5UMc'cq DUk B" l2j _ #,% GeDHS>Ud~3 ̐Ur`{:ۉ?, D+@nʛ*zTp-W:yԬl%9CdN|^ߥ(ʅ#@8Υc~\uԅIEEK)8W3twlH:w;!x6ƛexQ3I8P@GMNgߊQo |qORȈ ?|yV<`\1v"w?Y49>yic_ͷR B$;bY)#qp h.Xղm8~*!ͧ K?*/RF1Vg"4\Bϵ?`II"夳"HofkyCp)0,vw="a8 Q:4Rau\}"hg_o_D >,[ -9w!lXOle}X:.0ݮCTVݤ{2bȿOG C0=P:4ke@R Kh!\1*[G/~XV`ӀNQ,9JVT1M7XOHdާgRƎq ziVZ}*:ZKNBɕ d2閤M{+90[$ނ2 VЮ Ma;aaD.tIccEe.{+e/H@-g{#јm*aK ]|0}11w+3]P l<8qɪ9Bߓ({֢ʿed{!{I=y`0ߴݶ @8F3F[ Ŧʯ/YoR\Tw Nb#;^RYI3/E'n\\yG$ >18wa֣Wݸpm2,}T,آ]%MƣlHqiciSNR7~Ab>)$@~b|voO55fŤ{^=5)w _HpP[ii;ԊK)3p0]p".9Zey櫚t{͛^2 GI#1QeB RayW0rDɾzBfOؔ:?@؈jB94ClM *XRDuI̙X4V{9Պ'6mU;R¦ݵÐ-95&w}ynl)&̧a{'z]g d$B4-]Y7D~9)o^>oA!w - 9B߫HaJz}Nƒ^MٍM4W[yz*?g6"N[v-HJ8ek&0=QVPZD>,1/84j_lFbCAآ IHn~X̷w`f/m ̗ۢQ3Jv)á5U圚vJ+T4iR{rQ8)v YPYv~RW3Шd#<8Q|Qf꒑ye뒦gzCz vP&Ǜlqڽ"_O|$cUF 4AT\?"\n0gOv#h3V5a!6 N=/ A&NBR3CLwƭ}se/Tds`}@>CrzD[M([LuA?xRcROOJl6EӇ>V7_$Di`&)CR_'ʒzgQO‰JbPP3 =lyX;˝+Ԋ<ң/r! GI:!e|SiIo+[I^Wz&LFdbn:u/nBD0|lxD#kX( Z i/aoE'nZW{H G|OiD3!ⳋEpϱ\#e9|xL6?GI )Q SXSv1}/p=GQD2/{ԱK@y&CX%x szX}CTSQ`.@z[p9wRS* tea<6r5+,OdQ羸0bٱtv>ShZ;W(3ɩŖLvBOX]\RûR{Oۣyȼ`IT5ns(#(\1W?aʁ:CثU;aDvN1;@NYYX(0|G7rL4L,dDτ=įGaA0 u_Oܹ͐@r!V$18ZC^pIO#5GDzL e+oY4[] :^OmPBq%gFNQoEUʳ Q25>[ |ЙGp??H?+3A%ag1JsVyQpatr|!^d$W4= ').gSI>ԕ~ͫmF_e/%$CyuO.W\HIQ?,ۉi0鰆Iݓ0!ԝ ?C\ܔaTJ`=U$5o=>SPkbpɲ? %-utQ)e)x= yWx'(Ϗ]eCAX1kZoiNy)V& [s7;2xqș[N cP#J#{?ٸy\SH񏜲1 9"3eDA=ƒRzOq0C1yôrn_2>)c/wD&I1;ksN9a cU'UҸ(hޭWSu]F@.*TRjT^;9(NAX4j-(j; cC (|jǐX{] 38v-!bR$m!`I7";-h܋dsxROJ}'OJtq-!~@1uqSVSe pQ:VYH[SaAW`ʼx05<L"Mr DU2EE λCqRZ@c;YzwDI,~T%GM}Y}K#YX1 E)81Q yv J>X\Ur@Qx{N:T˛'*=*i{Y4&ΐm t-@h'.0-H3 ><*MT bːqo'$8>[i@VjSGT^c~ UR5- [>ƚ(Sᴕ~_֪ fP2qM!w̭}.M0 ~%r=?M;[=!ur 9M?+ܱeseB"]^Ayڛu8TLyOn]eךȣ歼Q8Lɓ1#ȇ Mx+ !?UYbH`]& 5Gh .YRvi$o}_]>Kl}!2*djkfY0EF礽S3gKǓ,M+:u p@59SfzzC*oue(Q*;mGzLXULxG E/\?d^ư4 `>/d30PQh34g]f._ ~iJ =j;Jd!Vn0:X#ȧts}9 vlB{Æa1AmJc8da P^h^1?LȿP|&2yA2k 7yjMK&P}^Q!MWFEg˽yTfqb􉤎h6pk#gd(V%[ *ߦ+k: .̹Х.If~ O!_4Ζvrm1mU*:}2 W- 3>Cf ?su@CZN/U ,~]$@_Es&2{Zfɰo8"$ϡG@}q@"*xbU;>eQҸ$lr4$Pp@oI"B"K`>ȜRO 'W>X ]g >MDyA OKfnZ]xYy|M/k zF槗x-WN:Is*]nnG5WmN޺IS|i_MzQJ.׿OGbgrSUa4- qkxp,?G* IwH` Lla.pLF1 `ٞF>1 K%0#>w/ u4EPwk ] Ϻ)N?AzΚ:~0:*Mt聾wr/qbF h=N2y a0)zϱVh"5 H>"i0zHo/zKHqOG*}L{$tٖаp!b ߰FʅG"]bV3i>󹈣Wepp=SȈ83qo0k${s~ [)ze@Hy/dC4'KJ%D>kӛEx.y+^G%-W':0X#eI*X hxݚݙQo4_ LJR1P>w 1ȄGI`P;zӴŅS teuI}%?7^Ϳg}EZ36 l^.âO>4[Een>!Me_hД.ծRI:֖O4&!A|o8 nFij?E|Sb۟ҕ):ϲUp~ #5ɈWԛF8ࢻ<[5^* `) _H!˻vymk##md*|ُ3N#kz{ƀoCV @3ĚҦVםV8k L2L>hL!ϙy9k9 N9{A΃]z/kwg,6++04]ԋDjLѪ ZcM'dCTqCEyEfo\T&eЍ$oKOI,LƟF+bT&)=)[XzNٰ4@!qȰ +"7_<47 GEt *'+:%8jͨQc˲7s=N wsѻ# ˪U.Јtf~J^fjA,ͼ)sメOʃ-ywD}NRӺ K%n{ScԵ} umED!'CĻl-GG`m.4d^DϤeaGbBؠHf:lB[J+6g}>|b{, Ofɶ0& | 4k"d*|w丹ـ͹_KmBA/SyH lYUUk}tHɵH6srjkNq^vWTuu;\a"d4A*i}+ua6ǻEGj~g鄪yPG PcA?b܉tdl⨐,v6\ܰ3GC&i-G"gS&UؙLaMS_yXv|pz ^P=/;!4Z),uo𚢩.^~<(K3)OXsV]o$?>xԁDVS[F*/@m㛢s ~Tғ ;7VJV K-Vik4)tѩ>;_(81i #PoTQJ#3ߗHO'Kqh^SECZ\i(%NNSb hrm͔2p8*?*\6u,{[`c! AuKC `(k8hUQʡR5izEn;Z_u[ȍIѺhhVw'=brچ+>mGNKVMhHBRda\C 1z`Gu&0npaowDwU"5d(|#O/1-akч!+3nx'z^(yOӧz.P_İ_S6A. w홢nMw:+!mBtG[uA~S0DެѼB?*y!6F>Mun1yS VJKk+3|?c#F"H}G)B^_]2ĥa?T"\`~V lKI/p7JN29hrn٧c5ȉhHiv lgwP1ꤗ4^cZ'XxJ)lNIKN:iĄOnn2 a,Ƶ ؽqaE!mf_! ʫ >Lu>$LFY["<~gG~iE>~_ܼpdm LoaG4:]bQeUsJ~~Ʒ $:Փ/rZ3DpWc: aL4]gYߴe%fbD zt`;hJ a59Fƌ?^?#|KC" w3xQ|Z>g* ;niEuQv?y; E>ɥw]̰\Ŵs#n(֡ݢ {? Ka\UvoUbxq IiUDuIǹN,0SwnZܝ@m)=nAғ pRX-:R&KDxDvqm8]wHVzܹ(^Jz(P B }=׻ʔbZh[ nCݲTЈkHB|L*s{ x틎KW,.F"IEգ3=Sqqb?Kz,a mP_pggAns>2er ..f3,$p<Kmݩ1+n% ,![y*ЀbF.K_zJc X)#wkIÛv6 T&%EU4|$~"]ɞ[zr`"[7'8K]Q|90P_dhŭ㳈C;rrٿnkf ǰq޵qɐtX=}~yΒrrƏk=oRKͮ\4@%|gMwZ9,RUjdb.V>_-w}o77y 4sD eI @)8O1.KK3 6R|ާH/q^:.y8ŁJ)y g@Ǻ?^; *Y88]B;/1[ oCq) gߢ>au4yk$r]> Q1@6RI5 #؆0,U_Ta$yWJ,G9"g!J\"a-=qL(-36xTXZTd>-<iRåo!b|.ΫSS;Na)L7r@ڛ<2/<ϕ~P*~D@ۯcryO|Яf(PAvB}'hG$qajsEd6*߅H?E`:РB}61\p<5c"d, Vb (ؑX- Pꄍyޯc_5Gn!mٹ< vt[p9P%4lj ⇃`U#Y\XK+x$3q ۫ )0eI8;9ݚ)McBe$>?Iqڶ;ck}Ζc&qs,AV{rǡ.3n@FÚrƲ 4&S0fl o|EnDN0 ?5ü_5ZrGM#I \4NE\!pEYkxMԣ7k a}_ PS&~,>Bswv{.>JzB#r0R A"q$V<&4~Au$܁2=ffR0>ȡw =xVFp8:TQde5pIYdsngk?cO*W.[ y> 5A6ʮN/IbPͳU?vxhyf1Sxkdg3iWC,#8biUo:$_-BiʿPQ!V٩A=|᷄Ma8F]aVր9HBnc_<Qɛ7ԞX5{jG-JZˏ-x@urSIrD}x( 2K51 ebV,FyqjLXNLuV+Su,}T?1L[e8ӸΪi]Ì}2ɣ13m\d^$,&tϮ98`jFC$Y皅T*~4ef'u|0%a:g2fҷىA$sœfKM6VҁZ0Mf s l-KCS+@X;Tv*JY-H. a%t${ȭJ"s ud=m9!ҥTu UFh`ᗇebPjHwhV}3+ΛGSc觗yJp@ңqV#Q&C)92Sa:‚55Yc2%;Pɼ铗p^m4B.G;s `ZrtI5{C;~@A2P6$pKR1/@U8 9 >a]_H-nO@axR W@0 mlTK{xh9Ugx>MKBJRmi R(ЪvmO;K(I !GworIbI4O\(š {?kTB*k#y1Fbuu,p2Vs=rhu̍}|`>Q˂܁GbC fܙ'z['hg*Mz~UKT\3pCҴӌgELDcl F O7 ulM 'sH|C/wU㹁`'-ߥ@r"gG<7U^nxC0d8!^RHAq`<ÿv2>ka‰%L}Ч?ȠDWbǤy5r/5ԗn6<_V ;2|.OfcMZC!7;|0Q"ke Bbd.%M$+ZOȆ1G΄ߜ]fi˩vb2}T_{GGMb]vjF\p.){;V4bʘ{!Q5>ies`G+n%1ؓR_7VΒʙ>X=U`ﴕ_fo QKƐ(?R(N]`ћAgo6@ }o"+"CkpɃ/U7H]ԁ 7 GBy8~gĔT膰"װ;%؃uxɞ}'@m=ԕ>!Aح'3:'<U;C|Jow%̄BSR{ fG<]?{[0]+/p|2vRqC%*x8ۛ:.FV-;Cݢ2J-}x_hUEQQgxddp܇5-FCӼ^]HJF-!:ɔ2|5c x6J-YpM^qd=@$\QNي?:25.w z1fPWM#nw1pE%,pc!ZBQ֮҆ ¬8hҷ\(a1'GKi١^6,D1:2nKz%F.b$ΆmL0Xu>QAڽ<:y6CUwWuY!ʁKX֌nkItCii51mkNV5C%7ŧ#bY.A>ڂ[ChD\!\6[D?3@jU$RmU$()g4rz*(' I2f\YC;)8?zPa6.?kdf`%&e1/J!CyXKi#;$3R^ -ؒ_=JٺI{Q^J/R[:=0tj!iw 3?›iyEEc`[̎Yl ,]` ٟP盠gMa],_f-3gb1*xR/ xz3Gf(YJ@a9Z3PXOWU"Qп}J]VN3rT}Trn$iMс^PĨؐBhnLi-.J}' ]oa[ԫ PS̸'T*/[ Bk<FYXJlmǵl<lj6| ff'jBe3aB#~nLZd˹5Mvy&5B5n#62_`Mvr_-mdHOkH`}=&B03W{ FPc)HF~!+ T瑽zݛ0 SxnPLŐ^!W-4Q}RF^@d8b}6IN G!x(c2@DZ M]e[2H!P5~z}r"'qqeT!$v-.cQ TZ 3~l;v\.,I`7 ۩\;d#x1U&>m ҵFSh\ؽȃ6Ј2]F%|c]4~W՚zLLeXP.edb+"*Cf0D,l*~Sm>zBmm,]*<s3t;5ȶ5xhr`BIAE+Vg޲*zǼ۵-uyؠ51L^]aS ሂ&0캼%q5W#HCh+ s PtKV}V;n{ .ɚq!O Uy_QcQ,gķq/XGz(."KĹv"g;H04AUq{8 kzNPBoQFB*}(J+4Mܗ#=WKW! -1YmR%Up.MZ* \Ԑ%߻}Ynm2&M ir U%26"Fm`5~%JG!teDrRhB4|a$rbQezV>'kjQNmZX \ b!Kh;Es[^Y@E*rdZHOк26L @3ٸ>CĪCva! mh dr9sܤ6 j< iw{"D–X0!d#]6dY#Kc@CfL<lYb(6[2мYQޣ4E@'h 4, V%P0"7C9c''wE~zf0]+{ףFE~ f!`dX(d| +gӲ%j)h?b91|끒*t# !DQr-%擇tdnd:>ޞ2qDXw"ޕ˴wkAZ]Bm-cл.MMGpw85Pܨv6nZ:i+xIQ3Rsϡ 沝)+)&+:D罃'7 I~|g*+.9,9kE"-zu&3ߓQ3K䵖FZ*#PL5ZؠY!0ġƬ{22wJJ2mFͨiEѩwd*Nؼ9ngC&j$Cb~R}Wxy p #>v쎹sʶ@w֐BgU7WilNB@0 *9fJJqMqq`u_ ۼH X/OcuL3A|.pSuYgۊ d7ur\Iwo}lLV=Iaӣf>)V +uo0SĂ*!)DX_"FstLQ f+FlIj CN>!G=f{?\bE~ sp ޯ.9ydyʝ1l翬 pm—q FvQ;d9pz'g55#'摰ia;!>-8LK\jgpvgwuv{|o":zh{d('j G(4Ӂ9㰠%p`Gb%#E}6!PXlω6m@xǛkh3 P0ׯ6:>G|{0 BӕB@W\|]\i:7  ~0+o/enXu(ՙf0-bvWCs=|: qtI>J# "N5t$4ew’ "+,q @A$ t%5{P:v?VPzŽ4oyD x@MD]W\ɖrb$ӳd'q%ughaty+wmC,pt$WmEA!䔓vEr)VS9 oN-Mgorhy?;q֣ 뙡(/p8#asbqw̛A }v3˂>)O$;Z7u6>¼XV L3M & %\J] /c/h-Nnnrޞͽ-w~:W^Q~]@51lL Q]^E5Gk8ArT?-xCG#8Ɨl1f38: #,O ZH]ΆSmF6utala9%TgD/Ac_ܩA6-@{ nL[bq3'Ms:*[q1~LY(r8becMcײsczGw#0h=/5 WKʓ"4+rPwD[ dKx n#.WX&视Be&3vBT݉Zg n0`CS8c >L\QYT%Y]NoDb=VA146CǙe2ˊFuiib/#ҺK=b,vfG̥*յeNnh_f'Y\\5a)@|a~-.lrx9#]wLLq~_÷MAaԣ uѪP*TW Ab) |E+`,$'^)rO&)q049x7`cꇡHi{xM!g#۔ylw>ƻkueyɒ1S ^/˾9la6u; \v>*t ()[yȦbD<Ŵr ԧ\ps*E97 \z721R\fu@;юۓT=Ԇ(|)/&ޢ;W&0Tk"xh~lW=5FD%%ӭW֫XEO?ә'7"$-Azq Ũe9$!HA˟i(zK G KO1p}WNpt'u/K{])@` EFt=o7!1^F ,ى8D3G6f&/sX¨(xu }2~^%"=2~poqAZ!6mF}hJ ,(2i⤿d,@ O1˪P8 Mv#E 'm!,+ 1[yhe^jKL}YVu7 3xlD`G>q Hյ,މ3qĎ?~)=Npp}7.8g]a?0u;Sl .| BJi}VJqe1E i`S#PBԣcjm^$eߨ!hR`sśG"]4t!ƁT5 ?ݕ"zG?qJxt)FXZ^FC{-\%!SIRe0j7OVHWAc-|"K[YcZz+_4f12"$ t#70bW,j`.P" 2uՒ|ZPz˻ ^9RVE9BSKUgbz7uYY#]6B0~>f"|m_x[6\WNOof H,$uO43$ή\LGl0uL+o”P8:ŽFTbnH[U";iZz(sWB˷ʔivUuJeOq^x˓>qP?5^e+TuGUE\0j;;Q塃C~éuM(x-ቜUXabJ[yp<TnG:]gi>J֗X72Ds>^ōV<\*Bf|εm{5tԻυA@չY\z2Cs=!ΕU*@in0H7կgvD-(^JpgG6@BP\7$7 hMb@OcR,fKnꌘ6T8d@`]: ϢN!-ʒnf^7-=4 Gͽ dc1`c-dw!GppN ۪zo%Hײsvxj&C<* S|56h+K5ۙ7-=|.=ϼE=aYza‘RQMh\鞱CTB3jYpLө/OɅA7Vi)C2D\R+/ݩ&?χ@@v\HDGJo y.f fj_Pf A4oyxw]< rE+gu--))qO,yN tFNQf>ÅzȒp#!+=bŌ٪(kW95}诒a6`q 3ơﳓf?2䋊g0ڍ-'PK.9~_6=:xPaUnh6}JL\j]ln*GQ`'3bkg/92A *; u "I]FJ0*B цد`T2h>v~۵u ؒD@B;)d4Da7Z]( B'qpNZ߷l1lƩƕEIDNFgp *l왘:V{ONx^?4f &9r\F>Tasc+["WD/fxM1>X?4,HeArR^ak4.*tdogy>BjŚJur1h?|TX҅ -ҮW|A]οWi옜Zষ txVܹ98o&oBl$kWGO7M\$,P06E1^v{FB=9KB ҫAu4 iѕ Σ(AS'">.ؿg.s;Sa`㴘އC-7PBpj 4'5c]fؚ{1?@IPjNaI:`iMQVXf't)DՈ_ĀJ/DO4oߕ+%9PXRkV5vi.WE ghk G<L 7* ? x1Q KN$!W'0%f5Bz>UA8-TFDBo,;A0><.#4kE*(( "kkS(iHE7 m۪\$X >׿yye"%gA04$[Ӑs֍Q 4h- 9_?KϗַD_D5(a:/sFPhrg^c:t`?-VHֆRbĒZ|[v_Oyr1Ƒ5ڐeZt.pEXr 3 Uƽy FH7}I8.@x~nU\~qڌ=c;V+Ï/3MkłxL5I_E;7ul>KoT܈԰<^*04l ]aoR O^zZ@ȶSvڰKڕwڨm#>vDeslQꃢ3 >Q/&U3H$H [P`AgDOz+(1=E]TO 䮶!?9 P- 8%y0y~4ug= 2YgfO `J9Dii]fy"~~aw@!&fNqWj_~i]IɁ )^ܟ !!iEon˒EA K.hE%p8K3vgFpr+MڐZ0\qnq.|  ؛ w"%(W[fk uƩ^vs#7nrK`X^Rp2DzWL"7'LNc4mgM,ruڌgh*1T8k'+~=/-}s[HL zŮ^;ѝK "`a?H8 yR }2 fkI-=+萚z?KxVGW8L=%G2qJNiz_/jSWt3F娶y3MN2Dst=\ o|9XXECc˴ZrN&@n=hZCqQ|{ PC} Bɿp|x):Cʊ$ \Po@؋[Lwx: {`þ9cHB Usvҩ3BUm'Zq:z!@ M=Z؋mYh~Wxi/@/dc0 |S# -o=D &Tgxޜ݇#HCuXO 04]%t!xcs|HiBS(,0,_OLP˥Tpp0Ld]ÂDd梭ۼu&lII Af(h,9P3 toC.Db \tW5@A}lE{nA"wG4Yґ& ~d-~,k1a gs } =`1ld%ztmr9\c?OeHݭ{\Y^󹓝[rGH?oPگҴ^I50JM\#[LljOzOPJ%\/v/r(D{ Oc4ceD`7G9?w5(v$Em}m ${͍k%.ŝ:P"jHMȩtj*E?WrőS m-VDQFxj'.3HS V$rQ%[dO)pօ'y 2X2na/4%Dd>OS4~k߾aia_#AY>& <[I!jkf(eÞB7U4vIƈ8!//tOT &qv=CO:='fޅcntTUC? LցyI°_%pb>̕y7Z!H!*I^i J-JE,Ϥ'ZobP BѢY{vkvOP?^juajš'CA*zAX_"6hfzXIrm!^8otYkbleρRyQ(d`vQ171U/-" NN`\d0vS-v;mM!"̆gK~]:8BMMt*QLpG~|rF+nK^&A;k)B;*)_ Jcr_m4([謇/CN%SΌgO\h>S?B6<.4[Bse=eqi6a47"k `=޹Y><@󔼫U\ۺ +X5Bz1&FU'>>\팴3=7-dDaU")PNi&S/^0ń|{ q&gWGqsӨ"QjFmLB+\Y`9ǞgNo9W%M(FO?}Cu4ddwnV?|JplP;<#lMr?6/2muevPܜӯ 1|}:(c,h HM>k)4Ԉj#x+1D=uM?xS\ p hC_"6@ H nW<*3K>AeR]y+ZDĕ]4kHl03&y>%% ʎE~u<^{ZA4ZCt΁BkGIp6|y!*W`Yl6RܣÔUpKfG\}kEYbQ|!=7! 2HI: IFj56K-(F!uJ[Z ]?t$\6{ >͉@Ane>ZO2gz ;)a=!?аĘgNOQ@TPތX$>ޤ,Hmzڤjz?QMl=ծHހuR{zYp5p7osrǂ14<<+խ-Y 9,HSRcGWcٖh gq: H+-pXغ'|K\ wZg+ϊLQcK 7T8>tY _%sC-@3Vn Er:yjۊ`ێQ~Z6 p+Jax5z!(_UֵhLpll$:/YbQ*f]'b;S ]*^b0G7{]V\iꖶt̃#h<>-V g ЖrpiR5H3X  ys^tǩGLc5];E- 40Rf]\(~M 3x%L'Co:&fA4$ΠȊqX.Z |OMUǸ% j~NA6.8Q :l0H} VK G%5 scNw)=C89/Eza1=2 rfQٺ>RP{1t1ɀՃ0@Iyr60v"CmKO`gIh4fa U:TcB6wzsb[ّn5M(q>myYklWGV`7[Q.sIL{Z\<tQ_Ԝ!k voAa?TUUk \yG2d J!~FNXUT@*ib>C\шk+p(ܡ, އye#ZWfFeȗo)B(i9#{&I!7 wrUV[_x q^#-SG}JC=4}cKd})p%jʤ N֎ipM}tnpLu~}k+] >[JݻEi:ll IXNLvӫ9?@ "cŢ3 HP 7h* Ϗ=H'CBI/C*tG4 H]~l3{\hvdthy+wF`x%-,&]Mk\-l:-8L>ı0NF s1x-w-ET38=s;m@J珼a 7=ƌG)ORC.hG.N 5CN8chc5W% kw*BĆa8Bgd9NV\a XC2躭F;@T6s{;DK2Lcܱ =9g;+\Η?WY3iBTpd(N# ޳cO~LEq/hy U[9cF*y174yo;B*,MoÿnϏ34hHEd18m_Lţex'f8z/-KPJ59b ;pN$()MWE ٛ*<ԱKXkqi$IoV@ 3…TamoYPϘji0_$E~*ɂBLԍ }/PڇT5{7{R$-U~hj ‚`\9A2AwyjLnq9 ) [-#75:kqN %Q(`TPu׽uES*!SL K)GD#,C#k}hZiƑS-/bda'3ld$t׽j9lAQ,6((P6(Pr1|ǍK>2-o+EXXo,%|%S[c鷛JaXZ?v[~1en5+ isM19s2^k/D){um/穂CKI?P չXTt̽$J?¬TRy{x9Ā~g *FdVv$vEhbf3s_ִ򇫘VyM]7T'U2-p|T:C'hGW*gJ.R l;S8b!8^M]Mrpɐ""<(-e :pǪ FKN:3᧭cq5)lA1'KI퟿˗N:NV{1_O#s SYJ\t|ذX]?5M VQa?aH@uRk8q&YLX(39́f?{Qy{g(mmxZwuhBA]Q[/@yfX,6LϐPҸJ7v4ј_ 7X'VC7R{;^NkM:wSy?|kbg^x]@~_uȭq]^úXlAHo#{satvpKז}ܲr"cJ 9 P~JʩHZ ËFXɩ pY̵i1qg6ücWp7v57.a)ZA'P0^ dU+lTzyoD$$xm*|'ib"Y(ڙ* IMŀCX/n@L\ ˱>ſI?jPy_h~ Lֻpޑ)^\}L_)rrv!zorm~'ꓬ(1Eӟr7m-t!5&`Z++t>r+EF#7f8ӘH7egWE73;6ı75D0EF=DKIJ~4DjNS "C͙NK7GHuIGvC/^(J ;( |2Ã'W_5.Ƹ\CݐOO:ĦLU~db.,fl҇x;oFES ;\,)V' b©{YH>>ܒ/>vʙ:t_k۷'d_!Rgf4rpaog%3 4홳WDC6 #Iccœ2(r7R#k\UM̃ "| cjw66SW-)T 6yr=*aa90Ef6zU3#VsHJx`~Fe_3YI gwl=y0rÚJBz̗}u;Akө!5_KZ0LQ{X]푪`)tÃukq;L]l#*ۭ.Jv57^!e > USV]gw@42L_HШ ):evu˔좺 DzPs|1ӷ&m:JVffW>9Wߎ:`4D\ 04Q/Z9^w%&ن pT7\E.QmrSvbԙ9"39/kծUco&7q`ǶT<uze,nw{T|_fc9C볔 &ct|HڴCzTuDGq>2b+E09uϡ+]y9ޯ]wVp8U7/-`⁾06 gAP}e|Fl{#MjG h/&}542FJN XWPj' 1k  cm05fsK; >wIH 3\)al^-ir=b ]e$vdHeSWRFX پ,P%2ĮmT2j%Z׀j݇\pPb`8/)`aR3z\$Eu@}7 }nsZ<=jv6?@3-׿+|J `(9(36{e)b.p%+fJd>w:{ Vojb cR7Md2֩>,z/tz!Wݦ>8S(&T!]Gθ;{W9ÌQ*T)N6SSwo@CRYAa_Z ʧ8} 6-p0[)Ġ?u vE@Cje` G.!PNYCwbx[NLX&m@V;Mn| *HDK=CƐq}IP:A3C3FTw*2`]HW▅CH ]yxʠ1E9,Z{\1\N82*!66"AgJm_dގΨcc_|h?z)T|&X%T@_0N$19' 7k(Ғ=ç[F+W3loΖa!('GVUЈ-'N;l~|JC9{!^<ӑzdvҪcvul1lTH$ /a̅$3 ?g=hd(PWnu~I S GutK1tF wp|XBtCBӝ9/${ ;6lp<"KC AIK05dP ?Õ\Μҿѣ1;B3-bK@+q `My兊+>: 3 >!OAHAêyAB"7:\ ! !J"'ZNr1;$ȟZ B-FA[^V vî`m+ccu[M}XJ(eZi}.w]%"q@WZRL8Kv !)WԧwGA\WյLc0UV9q:CŹu q% )aړ. N?s-qO/[@S'0HL^~uGƯ)p,-4quf还!ObwY{":}-8q̰ ?6RD+mÑ~G 4?9dy9&]2-9TD)ɹkEгyIݲYԷ{dSТ6ý2Z7I%FpSԆ p)05}δl2]u#*gl·W\I#c%@y:ɸ{y0u`Έ~t-q҂ C3GQn2K(]{n9cui h10iaSP@௑0ӯp|vS(Xΐ9_kMvUEJiS3eƮ~x>sڀpa2dxq:B|gչ̃c-5; @\ir"!f)Qsh C~ut5?Ib ,^2 qx} \p5mIsd/d_VbLȩ 7ez۾ssZ^J`yS8ĥqws-+%Qt, +j_3l??J#6s&)*2Ǟ D#4ߚ< M(LtOLCh/c?5.M’*8rZfVSSR^3s9N,>j1s΋KT;y|@1e i Tod <҇lpD}]_' :z/zasCY VWO*7B2Hs}'B*%_g' ?ԟC@4:xaKfuD!j9 '+-BZ>#gAOћ\sMk^jj{Ѩh(5]0,"rl!g'I0&Wf_s?:z^EN?dpIzq!h!!;i ]equՖqlM`ΘQt+NºmXhǼ=n .&aU?:QW58;FHR8JX反SXxcBu_S37 i^862ɞc eG>09 p_OtCyi ٤Qv !8e.KKjM'xEpmHߣ[} ,|4skscZ5; Npg!J޻'ɲ )&u-&!*,'7-ަ>ͿnMN6j9${ aU)s=Ş! :S%u5YNE`N%ۣ2J^B@8 ̺-Pa3tݱ87X>NLejriE+ %m!-LLK= /a4;S A[ߪUgˉ|$!a==3C:UZ ͙DA>joې\:X6h\Rzך&EpP6]azoye "`Luu,raqrKWP:IZ i*D;fϱ|HI?OzBR]p:+b!Ql=Ӽ A[܅Ϥoh|`CQZ;HGEco sK:w؄ M\Rb9mc8me]Ds)ETe!@~g=[(ƴ֐gjyVo*iq\UJ.f3S#axX/gTG!!q?t̥/yQ`?e ,1[N"Gw 8Qoñn!S}z:u7O &kO6cw+CuE3"]HXe_.[ Dd|~$T]'d{ S10. Lu>HMo7x{"`5]kU=wpƓvU92M!w`e(W?siYgW0;ٯo= )ߒ(g{G&Wչ窷o%P#<>iCe~ނƩF,ϸt~ X_(<*%}3rZCN)mdQ^ʼn0FS AH OUbNJYk?k9~T}`*NHKFOMW\7( ŸDuJ9G5{RP>VAfg8!nC kO ;ޔ|؍*h|Il4C\ I_@WGﲤԀLۧ ȃQ2DFҳ9-"Dn A` lv҂@8y:;͂/VӞUmWԒ06 {V6MDu`b4 &⥱ҝM'5O)Je+= Xr9?)Ⱦh: 'JYw¯Xp.OqRXCj_ r#AU'os! dM11fxYq,e3P~]E[p̹/M]u>H>V[VhiӲCZT)sE&L oDrY~YC3Ǿx#O54~8jq1 CKcڵi{R|ʮS#X?Dn# R""L0+¶Dr; V3ʗ]~(8& i~X2 -$92492ÂQ˔xo2*^3לm7_2Lk4AQ)ʶjSD*xQpM \u߹U" k8w)V2yS D\z:J~94,Y)T6,HB͛7I+[#k ~`/F*'1Q֔",βHcO#q79G< OԮ0K~fB? =8MYf2P//m&bSz p*5"%/Yv -0\i_bz+YjWQ'1Z'kК:(R/xTM+} XiN=gƌ +{S%=kG0?ҬV<-ILSr[/}9NTR_{Zg\kM,DQުw+$xAK5+ǴP);r9oa;̲WvLB}ap÷'&~>8Z3o#2u蹙"=y,/65Nx*`h9BAš4ے%=G9Ls\hʍRk6/{1@_%b] 韒4#0䩰8xڿUivk:yު*U„r0!%um]ev/w Rޒ|mݒ8*enhEm`b1 mѰ\ֿZ 7%=hJ{vp42QA}U6CԐ/,pwe&vHO ,msSH4jPH5Z{fĔ}'O]S b8ώƮWZzK2spDȓ]C?8ɁC&aHEMT)#!u|EM]ܻL B$V{\Q\[/{/ &ZqpaF_92 jׁg JFQNW]'5\Q7&_F> 1^.%lo8B9L$p7LTHZk6LD&sH{0##yUC ]fP?DDv:_M@pms`{Mb#@cXtrE2̓jR+)#Ҡe#9X6MC+3^'NX`;|Ϲ[!$]# d}Ų^ɸfgiJ供Y+CnmT#@N/ ȇ.{ֵ͗-2#uhQ_/ REuC>ru62#R8PJMrS>;hK-UfX'[~@LOV1B4orڽ$l]v]b-?/QZH 9(fXftCnW$`nUw9?~ xשtS]%b֛v>K6b?e eB瞈HFjJpXGLUԖʬLQˈۀvi;MZdpZgjhN% "!\`P[#| _H 9Yfr"Ap{ffmu{2* llNm{1bZנ)pSo)/x1Ŵݵ)Gǒ*ǢMB[ntx09 |LdJgh\1U$n_BqFC3dcPy 5CI_!:7LS(wQ*_ٟY|_ۯ¢a?ߕUݬc> sM!t9|ċv9F8*^܀](}cKSLL$^{yy+A>>yjy[v\z{R?Gj9Qr†n]s>o5S;g0{ #^ֺ4oqhRi|hľ BPMΙ)^n @kǰњh&rTr3/钧ͮ5@FnKgXt@eW©{=W-ꈦ&c:ՀĢ|dl$>K[Ε 2<4 {2.Dh^R[Yxi5FA)(뾊y}X;՞D'qC (ƘIT{CÇ1I/ Գm eElsZPZ9y:UٱU0S4Rs!H0@\;Qዺ%Yƨ!w3Bt,vb :}S_&xLLBSHk3rT8.>š!1on-8`ކ1O Jȅ> :訸rBdTn+%}m>>v).?|YCU0@bS~ض|'Yt 6H?!̐[%30`7ۦ`]kWr,֕68j+ZZt@)eZ퇆 BK\L%_=)a/".%L}a' U|^KqwrYl_PɢGm^Y|MZ]Y0 x%Js3KXRނns);P;Yl,{cZ.` >?g Jjp7 x<Ń/1 FCp (3= E ġ6,F'GC5ye}l\x/2: $Iu=k(ꜞ*]g:ՃѢLFX^bawsu._#S&TĉgC܋ă>f eǏ^TY6C 5{rLK xAE.wgQ^OCAgI E ŘZ(?4=G0YTxܶ\ LhӻU᛺P̜zҺt0gݹ]y{/O[U.RsB7}Y0DI2~p8N7 tDaLЊ.eiAĤ68GHڊL= ȫ[& δ*X't\+ tV|}t0I>HZ/MWX`AX<=&udxچ̿FU>V ^<ԡx\YYu\0/T+8+az~HU72|4}$C2(e ϴtӜE-y\B yt W<Η,%Ԝ"&&8.~Y?"k ]gEΚ±mTSt(aPAov RS{RhŜÉ09Cs߷{]~7%g],ްsI\i"Ÿ2VVI;A)c| Gi'j% e:`'@&)wqyH (c3[T'a0"m ]cA5-ۉk td\ju#=h[nTu|nel\/jjXDExDGaԣyᆲ}R|YLs\CRwفԸX%VX<ePv8kj)éO`ƽK&Ԥi/=R=kl.g$FG32l(.q߼QF^̙Ou?F=gE+z-H$ 2,zj9mVz;oưOG!wWAR4-pœ7 ^qSbwUa4cAO<41/Y'xRg"XWtq1,GCIg,jXqawW> coHSɴG:/l\.v@Q'_(N:jϠF ,Oƈ8uF%C芍+t-,Y·6y @jDȰ\ n=>̾r@Jf6]Aq鋠9)b~|p&yhqZ٦M` k:\3py))Qo\bmrAdoĨ8U_[-r$d-ewIA6v=z>Cb'wl87ўۺPMHy3~gPBqp\Ӄ%g%-'I[BєL؍;ЪCbFN#'S괍\ J:! $Kp몢;#zc0(+"vL5}}Ʈ9ӂt.sp)8Pm̀fh=4aV(s(S*rȅ͙`_B=/?b{: s$^E]v ]&n< 'cmC&i>𧵋;rL!L2$Q$1B]Y0m@nj-.pP^f"K0J~FKRKIrC7wO/bLA-Jf(QIlvٿ4kt(==GJ~t`^(R҅<1hTe3m_$}>npifyں'm]Aτ]۠aw,q?(VYѷTe:qځKWHOƥOQ>Cj^DIabL!Ϛ *ҏ۴ 51h:e$mis %Nc\~Ea#I1jV nfs+WW[iklm.,/:(+XpuYr/;@oz>)[==_xQ8]E_/y&Ӵu/ jxLkP'i9L-s=^V¢a}#fЫw/O(3 ݨdC0oìL2oMOa`HxONۺԋ0*uU^d">+VFnʿYRg2ϕ|aJkclh氊cDZjGFp=$ǑVƊ歹"[&9&NU5=W>c x;-9TgJN)t&+S5c#7~KA-p,^<K=]SX5N^ThA \.U% i`54/1H/ c'n#LۭȘ)H+AFH|Pa)L ?D}Nkj;{5=WAѶ**wApGqNr霚|qsoP//6,Eb[‹B pd[hqH#'%'u~?H Qr<"UgMɴqFn?f&,Wyք^X1*YbP\眇zH~'\⮠qd;$1!pz|ldD䚼f=L6xfh&+ A,/S7ߠH lhJ&]~Rdޭ^LaNx#P gۤfNOvH柃}P&76"q¡sخNJfU oUDl)'hW$wv2ޝ:xw!R9^>*jA;{rs2=73&Ԕb4v##Җ ,*u=eᱵ7ISI{Q3N;& U!^mL`d@Cr"<Bb(EKklp/X-~[|c#I"j<=w#ՐUFղ}Aڿ9gUHQSB!Q+!ETJ )SҲ/Mb4˧5m$[\:͵~iTBR 'qH|hſNL)Q_lP hB){ GIfF\92|7;gbY^%'{Kƈ݁,L ټ!b}4O`+_[+!җN=\fhD`7x a'y"~uZWΟ1a S9~OOyݼ֝TD("b&]6svQ'4_ !XE eMG9!ν/W_䎅_oBAR#sUikd\{m\([+UUUcOY-ijN+CD:󶦇;/1='1l*+<}uX!{> Ƕ"h_GEHEb|]z.%ݹVqM qԡ[V1YiÂ|&[? >_A^i@ zorqkN]^ѣeo?(&c6iT3Z9*yWGRP431$|>/u8~89?@S]y!. $TYTDR,ӏy"$des+ړ2!^zJ{62?y smxwО Ǻ4^5rHo;穑ۡz;22[VDQRl#Ʋ`bHBƑ5IW{_|{h>`zK kSPN9@)c ~Qg1Ǧe\i]*wfhBibDu8p|:7uOk}CNJD*&SW+9P1K$O&Ѫ1?K%ІbV*W ,N!1 5RYg oIwד]`;YvIB>fx2E-ahUk7%&#|~)xB8&w(6=U^]^kXY><&j8SQ8$\I"m\AY^2,%DqY0z RX DiSfȭA>@9f]O2hhs!vbECz+k aIF=u猄\%~ݺK$`@طϚL L&hUs>{>/j]CZt4}g3Yy`թ: MN/Dj 3twfVqˆMt݊u祙MX[Z>aEQQW^D`io2#ZsqðٯuK'l7DtUu!Yu]:C_Y̸Hߗ%gblq2O\?:< _` ڛ(5t5H)V6aDqޅJiKHo rם:伢?O o>{ *nx x;}!*iKP<ak2\:bre(H=G }ߡƬ'>7W*7>>J ^`2r~[ƃVaK1RsiDyk9Ufv&z45 lG_6#$* N'Ͻ+D 73Ϧ\^ţ_Xy*&,.\xkqlX:v7VT Qt)@:;,b4:;_tعK}de6AT4uۘq1zzlEYhLkf42^H j32=1`Am{@Ŏ].{1*ʩn/k44M+5N f0,/{'~<$D P}K<#ȴS/0WF'׻V.lRx!:3{VvNnC/=Fk犤+ mu pa2zJ {OAߓw.6 %\4ЊS*) 뭸6*!ݸtv~rqK~"(ôydуN/(fԹ9;[*sndBJ K u$HV5-Άu[b+2 jd-NYJԨ$&@3m籪 lpW:By>4;,k*YSL/~ť^l[=1X#r]T@k'rZ3jIKu Cx Ku 4MQ$#%hN2iƝJXx,۝3\dAznHVDOJWS*Zg鷇`[x;*;%Ea;bAJAiPp1vψ˝t mƽIX0%@u(F;vQuMv-!OX>7݃. ≔vn6E4!&b׷ hn͙03Y'z|(6fse} Nߑ/ȁ XK,;XOFQ*p*Rf`ԫUQx Yșb&‡>ό*0o ذ#w R>OHTewseVS0^aUl渉J׋;eBm.q6^8O @)09THxi;4 :5.vNTu*c:aOuPeG/ 5oM 9'm] j41D_(W6ԝ6띮>iui;ɂ3yb7AЪ0aP=|;# @m!u#cW|oRPE6pvig+#8;h+L Vðwɽ+E=K!##<D z-X~"+ŵa5.`m\10fU;uxrKE- Sx5@t!vo(dEw F],rRŷhIx0F"Cpo=lNT:?+34m -e_5\N%{ ‘p>?{:<9st#2N\ӯpv*(H+DZ߬SF$}ŋ:fDqGY&pS63(./Ti!7U=nݵK*sd:$=5:mRo+kb_OVʠͼ~W>Ĵ ? #u9oZJdۯwdz+Ё U b4ἙUm{P' G+*e2| Ljd<" 9E'[]BGd7V1>OAZ6RuCdkX(F0>p ZyG0AtKd/A䂝x`Nrv҃XԱP\sUiVIVQΨ=רv}EBł.ǂ/ B8CTG:)5Ţ'PWcH:F0b?AG.%LzyH6aV{}U2L'rks-l3}By^yDUY%Ql6{M!~x&DK lbVvf|*=@+C?4Z_*wwP<&R"OEM}Tr -q\^'1"i* KٞB5s8b%k͑O6z,B]-,p׈4Cf ǟV]fQjVx3[5alzc*% +7[_T SfM% >}vyj^p]6z]aΗjMZ%@g2#e}Ln)ݤ b5,]<%rL{md,^sֽ*E J6GtU0떊QZ沁JGcؠv29 #;`K}}Ye[a9Ѷ:c1U8SGxJ(;VinVt, o .yH2{^OF{/ue_i2a5hb:qtgc?hnxMS`o z(8tuKRjw#TD%6$`X;)ΞTN`d{q;[gCz6ChAafp)=93Te8XQe{\g oLmN9|;K~籓އ@t4 * \+˧{ j5,0:,Nph'bf:M4(X_3m[OJۯLp/l=I8".9f,Ƿ1 Bd:]z" JT KM 4}k<%6V;(ogu-51jpaҔq/d\d}]Z1N 6,mx/BkRozԫ*mKoEv}Jb 5DjWr4zx5HM>?5GvM]  _mb:z% 88H#g@_eA$"{x\&W01joou :bWN;< C7u0_l<  5^WJko")eGK *эq~JzɤcQUN&*<FY6CP`v&C֎[r%zxA^tMV2 6hkeIxmE8Њ%ˮͼ%jL,^ߘ~koP߼ 4s(drL 'S}kNjY˅nf#WdoM")0jc-@˕N *8vkP6v^6w(BdOxGayUt{_# $)Zt5v+ qet7v+U&eL1ڌ߼ Yri1^ZjaT+7.:c w] ӟhYBSG(;kǬd[܂%5ǝt暗A3;]t$-ktV?Q䷽^5"X 0c3si 7} ^\%hVQx;1w]>a[MBDY} S0?@orȽHp5!oYyl9ATIO8/R &i%%-ߒ=CDi69.R`&Ȉo2ب!ǴZg릃 Ŵ<b/-H뎨UJh},9aZܔ)&0NÅqPém{9 xn~a_~dIB4hEvd)Z3qWٶgx|œ01)Ͼ y_6QiBoΡjEw`m_J{: ĻUK߽6c4 9# Ֆ c)nHC'eKPv '6dR8@~5L*`bINRM;%$Rݛ?Ds-sͭ;:qǾ$k'cII07qz=tݍִCR 2m5z9B_uq mQ,HX3};2u#ZH +0^ T&ubGJ}bo@ƍ%2YמH򋐬,Y/(L٧b2\نiG]#mdiDr5$q  7*#D,a ݒWw޸Rww(b4&1j=9V펈E\O{H_sqWEܒ`),=[ќxFL~V @`s2L'122?$K=]x7tJix3%}cZ@r=hs5W/RA2c"~h;5ݨln-Ŗ7&_0wx SM+dYa*S{4 [)qB!9 r}f"0=jX< JUYf ;P`2& Ι;%0"-:Փ4bpBi=Z?|.Zl!p8=ܸ /ShEf^xԳQ:0I=4*' YhQg  C/<, l l̶e;Mzv[S ej+oSBVCCa9U%%T^H\޳܁ƈ{THqx!B)ĒnN60۶3 sx%/a 1(1ucF+BNpsŅ +kCzaJa ޗs$@cf?}.7)$[GQPH)L h%fa=yZzC;ۗ=U10c飐f \ө$i4U.,B/* tʹЋj&7-@dF!5'[$Ȝ_P mĚˁ?ɹd{˼P"k]șvkыX3ΏԓpS[FGxu"-z"EOYhvœJt{H{d0 8_s_O0 t.h3KdC >i$IXYW<8 M澿a"%(ٷ8MrT- o2ӻ?K&f-狷x`k{o5?I}ѣ͞\RGԼ9Sut+#=Y#[Z'&?6Sԅ$ ʻ|Y ^ABtb0mFAS!bȼo_C's7HfNuˣ¥!̱x :46MaNhvc:q1jiSԓ]#2jZ\7`snWcinLmX3'dy+4P`-Xljv/(-GTeucT]ګ8bQ,"|jo6N h[ R C;TSXOS%cC{ib_|%*JݭEǵCi~/Mt=8Ȧ2*U?i{=# yLئokf'3ezVI*Vvl8:1-#Ҧ ] B c_vtE^?wT9;Tozag~{P ˄_e޶?ݥ'^)X}o6.+k7+fJGQm`\]Q re `Zq.LI0b9:q)/N2u4rlQ5 F{ז~םKDӹUŕ׌}ģLO *ޒ:P$g z+7Y5HU`[bH4!%oI=E1c`S᣼m}N-fQNfe7B~5Ѳ̆5/@BuU>);%xCH;ucipze_lL%>_iW0E:L_ЙCګSz"#`Nޙ;=U[v rkcא@e0 *eūl)QVxLi )rRDlp? ewն“_V>u{YjͰ5HTÏG_ZOwGn_ mplEnцc+~~XĖ,;BO,}!;:΢]-aPCV=^Res+wyɕ7$XލRtzcP bd09VA_mrLiJGfnN0ʳW*Sأoc|eVM5Mno- ՝cbF~^hȜu;G{U]{n+@K+hkU@ϸr~yLUY^݁/>?>eOi2nBv2Su$gİ-|De)DV2bޠ&P~[)W$~NP'&Duԩ62-P7 {[%&+(\G\uW҇۲i*Ţ L~ώB4=6ʔ+ ͚8W 0:YYS7ܾ}wBk^Vl-Fpsp8GE66Ug :C;"h7uƪ^ODj<-\x!ހCŻ, ؄ \1=$@`tLCrA/gxF1drnVWs-{95afy,Zj@5`bLbOleUcp_lZ^s#ҳDt <<&Ka_./ qJ2#MPk,+rͻ$׫>֋o? T|e9bZ4 pA+mk,=?л. B?APR ̮ I2/p=ΐ4Yvw;Ll ""})=? %FXdkp /Kb_.qצ2`(jhB KϪY7Jzߪw{"֡GՌkN!Qll>sHz~oWLnNTQ\}AJFsQ`~)Xc!k>2{!'9wκJ3- QPĆ,݁\BJ)#~̇Cט) E^Ҡb?:Aȸi Ek.]6?$5Bq)ühz'hpbTe @ܖ^ z.V@1P}Fg1~ EƲf&aox\K\ )vK'{k8Ek 0Ur˛@G'0UcA"e2yyXα8R# 14puLjg} 6"pM0gk,pfj?JhC1 1b[꫎+[x6"&d9p|$PMI}.}r;V,xiď:38F@ ]t)R'mމehqλ K)(U+0.N3% ¨ztVXZI}1iH4VPQ4m_-Og Ƭa5(e~}rymٯLˤCdH>v4tp 6DֱGTEe{MHh *Bezx!Ze.CzvVޜiQh  #|&c.+Հ;P^1kfid6w Ϝn=l*VDd k+P4}:9>-n9>Ԃpa_jw“Z>6%}dqw "O\)jw\5ԀuIkL xw:,pquBc˃C^̽]*hX:"p1. \<e<ESX<os69w8b`1 O/6mэDʅ4.q#ۿ˷=2 GoE1B u8Jm3ń5{9FtVb&1([h$)}9Bn_؅z&k(\TV, _/rR8~WEݫ9՘)(Pa(Fu]~bC\`di|I J_kퟦ_HCtFԩ h.JXJ]4AIˎ*bqVD= z,1 /(W)B˗NNFemӭ"LY>}Lq/nJNk0} )7^@m|c5e.6ҹI/FFŮ ̮R)`0AO~=(4֝F_' Ny |9l 4ј=MKeݥe9k# m.N=oe%Vpor|)f7}JEg  3:VvEin5ۧn͜0Y?wz@41rp)Jec{.ڵ ?];{epR|UH[>_x^ur iZ*3ɖ,蝜y+CpޑvwZ[BF,a||\'|[-ǺLLߐ,턻s#Vj 4Tk:|ec.Ov(鍮f |2ˮ Iu g3_so(rīfNΕ2Ƞ0zFRt:>˲SfP"?pKDJc. WY>dx^C=esYw>Y<\P}Ao9gଲ+qi%Kn:C`ֈN@&'s)>ĉ><e߲iw$ʾl7l&۸^wNf=~MV+-7E%m]uO[e1/q[@֊Pf' E\X'Sg2J.|[k W!MU+K]}M#@-w#B7l2TI򋌼ucT7qwS![k_zp.L@uy|' O#~80c@>e8YGêA]{^DLtDȆ~1Qaa]ux=.mAfPcvDlH:͵yu"qφ=v[CQ.*c1UՈ7ˊ)l42AdɆ#$^ezyS7& q#@'+=lhR fZM Kണ?d/'BPU{'.ލ"l蘐цiP(8ťS"WD*&`HboD((96DۘcZYi_R?@N$U~' WicFg%l dTP/bgO#BG*r3 {%zrww~*yA 81 (B%a?%U 2ҩR|&9f50KKy ; UVǣǤkC׬!xCnZ֡u.m*r*Û, K|ڢҒ% CAS p _4NlC"9O¸L `8d4P$Kxdm f9kͼ_TQDmze,.M)e(cs2)NixOQËe :ګi?nuh}اTCeY& {` وO%C6tz *[i_8I͟%Տ7FR(SYݑG\'b쥎@,oJ=@1KGhb >1 Al1|1z>z69t79ضV)OispY36?15a|ٯ ^e]OqhtZ;p*&, aY>j &GB (Y}8h O짎;Oﱑ%C$\UN (sYtL;G(1hەu*]b{[DT &3GUa΁KqFY5SI3Ф0N ,U?w%2ӄe.4\IM3)N Bt+}8a' m% wNӰkK{b~@`[GD#AW5&zHH*% |f]a_SOJ:[(2Qpx}=8<4 sYaLјS}%]ep]n3KΪMV|vhU[@#lN2u 994 I[wv[IRž12MjtՌ_3{ybK:ߔA]e'8vn 0uc<[FWckXpb jD\ msMJOdӞcD =bL/]%/=O&E4Mp}="?7mxKo F.:?ӡ*&GIً]/aGu`ܸy:X Y̏V(b0meM\٭s8E,4E}`Q!ZDzg<8iF ۩ Ǘ'(QPz\M9n0p2Zsn̬-Qr[5IA%e[Xa"{nB꿇1YzıL"V f 4*[.r40|+`kƖqȿ^||6ڃJn 1uTce@ k/2d0Hl.FݪhTS QbG1JXhVơm}g/]RCIK eek v53$%,-xֈ[gm[enz?'.Ǭ,Z긆.{\#"`#D@Vj8#\.aJW &K-ΔJuu]?#Dk)̡-,L&0>J'm4=4wjpUPoKr֣\2N,y:]}7Ru WAyn ۲ш}{ Xjt'u"AW40ߪݮ!_+U<1^kGO@Aekh1n]vl\Df޾S.ɰ 4* Q2 & vㄚ'tX^y9pY=\j+jIuITUʘD'8ik2 R!/DzU|v*'舅&?9^@,9'} "d ߐ9gsϙUe mz a-=-{TUMY&8sdSmf43)a=(FV&icFQܿ5a8؆8L2zULL!S6+a a@(Ws~^X]yLBՊjDH)7*Y-9 o;'ipIȑ-4Lc{re|Nt9X7 WbFs=D7?)7[-;aWj֫o Q{ Bz dUJ*7{ (9L7+ Ǥق$u\hL f$ن1_LCdu>p.*QTMyJ0٠ZXng:ѬE8B Qmzdô/ ,Q> HW t,Dܤ|\ pU&њ1'H'2Ԅ3"2 JЀ)d?537v٠^~*<2D n߭/!qTv֌+ֿׅFɷ[Fsg:XN?@ڷlaaz`pY7%S%݊X4(-ZIo` )ggAÇ)SI9 DRDTu!gfCX\Gh\梇wA2Hւ& Gh/ `fظDa{~les>V49ȃeu谛_Dûf쥞UknbIcqM 'Jإ.>Uf}g\M=qA6=99OHХ 5')} CQ\smLrm֕842ؔ=l*TTI OmQض3wMFL|jo{=+k+/ݔ"[9\Lp4Gb<5c Lv&Lsx1Rg_0~dc|4QcO䉻rORC6'&z|l&6IVDe}Nl&ވ  ]_$ 3cm{+Wp%}ݥ|h0:eɆLNWvV" |u O䩁T}~iG  TTJź72I*X0z7VTբ[X*OG8&6!]$_9}(*2^`KeU<7mKy) ;RIU6ۡ'juoha.#N%ZVL|3&:,^m`|W&' ܥuC1L2tFhURLk=1{&U" LvX^0q]1?-6{@`үy[:GUA{!3+t?\6͂X3ڻLJgHu:?+њlD3Sz#IxjDƄ]صQ_U5[Tkf[\mՔ} 6|2R#"Y[ 6 O*GMܨoX6 dRE!^D\">ψ Q/Z,~)º##.*!^Led'1JɻW0)>m\^Y~YN (A9\4g+Udo9lLmG  3`Qocy&lFZd~mꯤt L6gpGD5#u@|2%2|!&KdWR|KWs[1Ă ~ ؈@)aɎYwKWƋ(U8h6IU ɉa1\o𽤶]tiOTqDOga>~h]!|96Ô1'd"Q:3u_&+!{|ݲfB`an @oqu0Y0q` 4ś>: /51-INc唙[W/B}&9\eٱ{ezyEpذ0lXjPn&xfhaqd*&z;ɗP/-TqFor`sԣ%qC!YcLhk: Zx%|urw,+؏wvF @8.X УkXfi9'g dVb: <3ȅ!34`I l [P6h5P+o,ޅ]?7{Q埨QhHx@2db6|X3s9\h ?m?ey>nR8sʄB$^E'mdk䵄9a/|}{Lc:@em/W`=]2w&(BΒSH 48-ss[r#)E]*/ۄ#NzҎ7Ze#Xr wdUF%ֲћA\"hXd6&(NFRsh,xύfrpW! _V ,:]9OsH8f_lӇ$_F:K%*гl$}$~h;Yk=D?߰T_&+7:CN(V}hJ!l$cD{ Emw'qJ~2!oUkp9!@|j(znkU!b$ (w{h+"_H0Z(`9EN%K55z7 4d ",;Y[:yg"S J5Љ5b%U}5]ᖇX7Em0r)5!p4f΋,aO[yAyI%4b%7ChGLiM߹x^Q#CZq%ŷ9pU}0@,]j'1 LEi7NYbj=ɳ4;@VV6bteV,* DSGUa/! :FiW+rz bŶI-$r?گ__9\Me/]h[ytiEI`)vmqݍk9@[#5;?)[8G0$Kagӡ\,Z,(}XB@4Qsb)1?1)tOt)M$tߔ?é=Ì4=\j"j7N .{0k.MXƆǦku eGEG,qE+pX{HC.ņ׋w[)WavpOmY,@0i _e*5mH=)6ic&% UNMo6d CЬNK~AַX! NK׶jr.&\A}p&Ioٍ!ԃh<6⧐KE7^ j^Dc1\~'D^5BUƇs;mj_+G;)5y2Q(<<>߭7k<;X|WW; -i IUj@_5[&JȨ7$<\ON1\+s&PE, i{z'v,jRjssZ,kEa";f``65\?32[Mm; V2b2'Ԭ%:!R D6qD O3C%^bӰ.l*Ϗp} d)UETy:ENMd7+ WvTv܎+q2ђAGu+y($C^|LuLhJ=;aU2*=,\3plB ,&k|(?ꋏ'PNd2d޲Yժ6͜a3 6XJXtc(,'X! =Ȥ!$1 l|,b ZxVY&ݿ5"x/-<"Ti` t`#T-ޛ;D_J(k$˜9UvYتb'጑jɣRb\^AU2;фl4Nb0ZӀ RR) ۃ%L>vQ>e-(Vo.:T &#84XL4*Qyn48<8 7 mn/󞛥 @P|38 d kLpi^*7ԋJٶc| *DY:*m(L/' d2h%H:}|)Dq:q؜c ´yF}U+&RZ|oL+=29쁥A AWuRXN_w݉pcai3%ljBO}z[Z1 sU;;K%y(=`+F /T|甏U{=~ˆЁ`BBW:6Mx$k==|45٘3[Pv^$tf>$DGK`K݉ol.>KiDMmKݟkY*N z)˭w(@1@tSȖcõ $TsOz{~p}YYӐAAISGlY[JyX $K|jN}Oq/t puxu+!_)bk1&LڂE jPtPeE9K90(.Io~e׽8dH8w d *P{fdī" ]*ԟ4e1Jx&~dl JNl'~:[pf:2X` V M2-e0i?HeO;&hK%ѐcz%)e!j%ѨeP01wdrA'rԒ>i\] C-4 Av}=}M$kj\;zR5)=^ojCCq,/¶g͋`y=f5iyTW\˸=]7{PĿ49'+C+ XsfFN7TzyprNN.koF?lm}UF9h SÊL,cgJ4N[7v_ {!nT̬,D6,?JQd1G…iGgGưݬ`Xy~slH(U7c*$ruY0D4 Su<]LMo\uIFzܸu{PnWX-cӂ?ےXP)Y6BIc_ǁƷ/2y ɀ^ga&zF`Nl^2U_D@^-2r:l\ .UyV4/A2lw{qݮ;=Jj/﹍N_=c_h,8Ե^ (Z{C'&l6Dے):}|N5K2M ] 7'߶C/+7a m 0cnyQY81Aֽ@vޠD3YGeTJ8Kҳ=ίy&*,W*> }gv @嚃`Rp#Fkvn=K})F|.E!=K(|+F$m1BɎŮbWfdAEq%vm`sp{K7+vrVyD" TH,@ sk/ p=e@>8 [5ۑr8 g;4 xDr!$ ymvj UBv BUOcR{:4=Ba35X@㿓;:V읛iiFiQ9 Swq<$9ucx̓K+]YpގV?̏QDn0eZ sttcAES{+V誵E}"`mn&C|e_^M䷺9}2njc;tG tZ Y׵bXpk@y+?&瞔rb%g8m`*x*B{{Vqukf# >pV^n4uW1f]̈i5=m aCIo` 0G\3@Fpp7\} T=p5]ZcQo''_{Kϳ'$C-oᵫ{8]cU뉣[ݷT-/Hյ[Z;G1 p }{[F&>~_̿5ծ5J")E-DG_dpH19~Ca:*l]M=+ A6q)63m(N: jUAnS)6;4(]| -^@wc^S`ŰC(.Uqd&:b /6\x&wm}`#Osr K&q0ؿIgqغػNTA\LF9o6נx!ψ(ZS5h+$}PKR"$UZ)yFʰQvzL SPjpF툂^ܢsO{[zzSN@hUXG>7F +|f|Qsy^ulzl2l:~Ֆr{iAj^xd{uޓd)JN Йbef (oq2;>Ifj([87)/cbp k'~G鬒,]$ET+^ $`V'/19ns`Hf jK%z",_ƸϑQn~*kQ:@nue \L ګBdȜi4)y<+=,H|;]6NBhIUMi$4L^ey۝+$Xg''@ oTaewɌ~tZ=/4A;Ꮫ4,汉X;^/]iDWHTṇ87 ~!ٍgb-?!K8G"-a֓d׉fId/Ԥ/gx5br]b~DW^n ZBXE8"rpqZ$Zhg]S"ABkeޖ_"v'n}ܚƎ)Iĉv]Yq^' sm'ߕo#fMaőg!rbPg /]X>|G+WqCQ*tr^Y Hђt>K_ 歿RQ  UNM)n+N|m-ƳN_m\DH9aH;%n0uwƒmCܱ2ͫ}e „&PV| q`N@_걟B5~uٴFxL@ΎnWÝ;g@,ooօDpIXQ%{zA0a1_D!Ua+ՈMͰyAF69XQ];Oa,@p*Y"?Tx܋>ƫlP闏&`mCn@iM#f6[]7.Uط,< vٕ;*D)-@2]3.}`؁О~l8Zϓٯh +68XrvIV16muz^SSLr|5؅I+iQa@4b@$9_ .W'ǂqRqg= kTDYQcopRcīD$#:@P[cO\yi@,1 0cErj6twB/+A_tYUfȨ=[4Ϙ{;M3 X\h)bRP#"{ NPb.)*YULr\%j9BbD/[$4Ap'[q2<Ґ[᭗q1e#`QR[8OEh<~>;ngul0ג<7Oq@XLs;n17Fl\Cl'ڨ45®c71ά{#$Lzƌ7D P 4cBKI=@9,6~UHJVٸU%Ob-F9S{5puL5]BmX+JjKN/RR )7C^PMk{0Ȱ߫PlXPKse>:91 w/iw7]R Kܪڝ)s;؟@.(@jaD-jF a4 +A23V6r|;kTZNV^}8L }@֎;ŸFZ 0YYJmb H/L3ɐ>:C3()<~ѻAae==3D) tHsp,e8LP BAdwRgRnzŜH{x˯.ぉ1^17^VhZH^_(`YD6)}᮰rOjOY4vHرb_n > 5ʼnB(7ua$,/TͧحWN@2-'9`"yE砥VZ ݊/ 8~*?vo] `P:wVg&4!&A9YSTƕn gpC}t9mbDбQ;kc*A|ڭu9Fh30 ?:6J/o` Ҫ{x2a,vMJO`  pHq"x4Sc<{'$D? 9?8(WdO깷$fU*t6H?(3?Μ Iy /֤9==mTxV 7]q"gw.laR tM<߰x Y34y닆NtꈋP%@70\0ANɚRi<q;,p-0 ^}vP!ۿW9Leٖ óZ4Mن{%-jmGcW[Q$' it^3Z==X`o̸᛫8D '4 zX fT[Dɧ&)窸P8=2ɐ' MT.(חgovP-.qNyUw,URU$}^YgIyjaV$1&y !FiZZ$XEqihP;] ]i8ٚ85crtgŘ (r!_U8o}.9iM3WSG˩E^ ;'݄k#LY_ }#4DLLytm^Y$?@EaGٞ ]<$٧weɲks]D-y"Ѷz']@=uZՃP/vE)guzǽ?޼0rӋ` ‰T1҉=1򞥿uF(qS0|'T[*#,Ը{0JA0Al{*?KBU,JѝT a4!Ȩ c 6/JT:K>1 3r+F#zUdPE%[,Y8xXGM30G)ţG: \v'"'CM)ɦafd3N̓]+m@h&/Stml\[ZRA0hpP3FukVe8[AtqqgtQ"Qes{d2x&+@X2nij1ąveޤt-& ]P[@uit]O[L4:z;9u c棽1|T_Z)63q3E7;3/ZFmj,I,N]ja]gCo"ӎ48GC$E#H^L/Kd]ke !Eoһ~@`ٵOn| ;WB'7>KςvF_G93/ MCGR<}w' Zĉ&hMf.G,ɚ& aDz32E!#٫O:$mx5SMT%TC()[EHW| /G>N /)ٮ??CnJskO6:6U19RoWnX@[=3,)?S; |e5=[__at+`ΓJ ߘ|(åGjsmS0 0X)'~AqG<=ƞw)z9>R,b8aX鲛^ȗ$;\,p;>aן%qN3/`B\4X!:dv] i9ϵTR=a頫eX-Y6dvoM 7$VNos^| E{Zm;[!9+M!zzQX B;`M Mu F:0y`Ls+=N&] e؀w.-:9XC{`p`T;ಋDg0Ȋ5 U~~dB7fx:,~%cY# uےsOUNs YmpjW^3׺IftȇxI㪕6%;J'P~#V]ez xKu)d ˣU BM Q[N[`pN҃m|8ݩ%1ѣ@[y-E- 1}OmMFv$ӍVC*ΏeztZ:Q[OL˧ٺ|+ķag[̶J5,Con^B+0GfQݓ,d9eFf em7fZ8>`ŤY ZHiXgG;Pް<v0RrH2i XgsE%ܞ"{?/1i }gI̴}[4@!1v8cO`&|ٕkHL*8E`ڑg#R4l8E??"zu4鑩ܡO&!:(/T(F *4؍mXϤ(6T%4pF΢GX-!358Ǥr̓*as4HQ85F^ 'ՀZ|14˺И=/ )KP^)~wjKx׽L-ӟwՇDjJʙ>aKEH[3 iN_lSH_d Y-*_(!2w?-Ib+-~ٖ6\(æs]ֆ^7KkB'4q S2#$nEMR Pe`KWw% J"Lwae1E1(߬\]|ybAML>&9jL#CG2B_WT̂^L/?S9+Y⫌ு}ạ)싂El}r/[FʚVoX3Y6Eyr8{R^-BFW}5u4|P `f=b!k>څ ,}Z `Rxji#H9l2]/J~e?&ZVĈ1S# %teFFjZ4^ZLHjگʉ~&rهK |%W;E*&\ ݓ[l^[i9R`HkInդ?t-\n?3N7QF)OPNqk=У@J8U h/ wGrIN0-< =\X3L:X^CMK &Tm}83Ln.b0""4%,JR ?&CH|]9~nHZCDPG el:!ڰ;L,<,`D#_3\x6I}[hyH [;;>G<}31quu Sjkn&B8HK뼲7f16hK :餯.K//d^oθKKҒ$h^lO<϶*~|Wo-qd+6kdomJa`5ra |TNCGV (3ʛ>LʤO r5 E$SLGɑ<1&헓^+Pnr?N")/ .;,,3Ř{"Le䰍cW=ETî3WGAJpz#Cn{Ef8 uUgr@զ<8 .:AC<7T{å$\Sy 9mbl{ HtGm^` S ͢x!&?odƊؼVygF$i_u^s oZȩdsDdmC3)jVV5g\ Sݩv]C08;,bJ`,O%]muox9Ѻ̏ʎ77󃤩^~`\rz%#dYu#j>k &ib- {,)\Ȱ<܀ y! q7we ekZUk̸QR-,[oXLBΜv2w=|"#)'2:{7':Y吷,^rIL S;>N77yYnDҬ z>i1l~UZ c[3U~p9q:Jjx^gIpXQ3;l> ?,h9SU-@?6ةgTcs8¢҄"J9 VnW65,m>1!F1 &Ѻɲ}cPv&*!;;R[O' 4b8h|GuX`L! ˿48|hxkEn75i^c<33w=B{Y2ɹ>>Sb=eO0FӀ`8NpS(1ºYXIY1hlm,ΑeNM۾:/RX~Y]̳.'.JIp`C )Re[HOυJ B9&@&?AZ8H0 .a7S筠R{Y͗cBx?yQS陬*Fna`<'5>]cd?9%l'5sF20Ϲ/0"C{Zq+zK`L?Q6'YybXDO6Gb#9gf5?[CH oLii;B$53s*u5l(ӈHOI7M .0#!eQ{Ȏr(b ɆبU= W8_Te ~ P4AWxC/V Rh#t9p˩jl,O-XT*,a, 8z[hd ; 3+  QfF4Y)qvO+ HfxLeu1{43re#0V2IzXBr/1vuui:Of {P;|2AUQIH/FQǶA?e>&NUN!n]OlP\~ l(+b|5lQY~oo*^Xot'(%ZN789 2Z81kTũRI 7_Xך1 8M'C(ĂxlzYY(IAE󊬦;d@RqIsp`h7ק--pf\tX;k4m6wZu} #H3vR=ބ]& X'-bD *ib'jhWUHhL0ϱ`Z?9HA3C`uTU]'TKc.nHZ#yɪ_ z;Cqc5Fo/ v޼ 7Ddp8v)L,3Ovz_v"qb6)ag'\WKa/۰88F X~XJ/Smpyr>v?K5~Jgxo=C\h2c2If'F&D: ݯWDZ #"^,I!cf|;G}$\M*wɛ/)݇ Ĵ+Ui#*"xUBy28~Ks뢮*C8r4Vq"[0Dmw($!_*"q~ˋf2AECLn{̀T95,hP12U20 oPi<6Oyl֠"=]M^z(la_eNZ} l=" 2 ͺN1F3v v`PU b\W6S='u1iCOLrG tȪFc|J5ꎴJ?+D7kWhOs'֓f hFea*xG(eoVZR5wv総Ds3ALُeuVfW}ItX1؊W772 1JsO[A' rsb[U[l9woG.+kF߃<[YJT(u EreHHR 9'].1v V{죰T͘>9B~v#ɧ\Yoezoa͍7-u[S>_]kA}q:j'mBF[J1BYP.c~\D nuP1OL)Y!=kVfOP|7sQ\׿ v6V?K%?Ky*Q6rzB,P.(4|'7;W.|OY"fNrvffC.A&I"ա4E rId΢'A#wEw%;+r4483Pv ǝbl;]мrr)D5hz;p`ǰZӨV8DFwbncP@F({MPĹjT=kHlꐙHDgd1ue)OIO(F#lt03Fla{ޜJg^($uh*Y pl 4d¿/O< Zi(˦vi Rh._o:OkTqL["Qub@- QB :!a0hvGԌFq=}fks4nD eHԡ[V%p# 2Jm'/JN~բoU,{Wmɇx]OCl$ٙ^:P<7[]\wn4[Zt cu59T*uȔk݄q6JS1'/=>f&kT.g_^ⷤExwDzY!fx 2_2f`3.v ~@NU0_qgWh1;f}2 9x ^Lq>OlAYe7g>%T_ݓov\W4AaO'⡂h.jl5cB9]kL9]KsmNDGUp*j4wsB EJb]GpS$2f^Ҕ}ȭ]"7% jٕ=)ī S fv#4Z3W6,Ğw9~T;fO']a"" s%9puUl£#_i'>'W;uyf mC>!]&Hzi*FTj+Ta&$Idh{I0591d"\# zm?N+7@%mXZukY }cj yz\1D[:UrR(k~Lʝ(vhC(q5xn"U%t7y?W.Ŕ6ҢFVS3CoU̎p; 4|U#@3.PJ5В^w% Tv:/>5HFE8b^Cβ b(Xj]wxK}f4U=M jAւ8o1+oii99uiW{D4.ͣ^W^y苭V q57 ej0K؟73;4Rfs"?f*ߗB7] rYfpY'Tl#[5" 6e@ ن0y9G +Z:W{b踣b\v\fv::#κ2Hk) |MFջS3*5 y^vXt[r(ŃT^;qη(KO@Dar˼ZZ͘G7MaAIa 8Gz(iO8Ȣ#9v->o%E^؞rЇ}wPCrDecH$j\M~\0eSnZݲ=uS6Skx4'~(p 4U݊޼p} Lg6݄J7Ň/R_DM6' a?+3 6bo<9z1I}_~ܽ %s퍇+ӺJ!ӳK BYܕD֕BH?!-Xi$\'c(X8頵f. j mp;ifo0|Z7lџNm3DF(';'mJN;(QܒT{])V3_xl7ݞcy܍k`AXZW)m ]d܂#- ,noG/q{yAj(K+#c+;rY?ki*CGe7~bU>>.3mpHyvCY3-޸Z]\q$бՋoj)FYohK00`;9ٖyyoܚpN*D_QR`XŬY92HTA|vM//Fņ]iR3S<|"Q}7TCFJs]!q_S~nR~#@3᪷xDrmMP~m4D {큰b.rw1 NdRk  _sFQ/c(^ ;p _r'À縢&SFij{1HlXdbUEӯ~)-ݲfE],٫+tGqZz}v&[ϱ0{&6IO4F041;z47UviBQ4p䰨Ο\RN(yȫPoftdXES7:*Cd,SHM',L O(3$5Q*\O*vR o|UHZu*ۭY)(rFX",6bKYB;CɊ!@ϔ^eM. 5=fP6֐Bި.al~-UiIR:MxLUXXӲ @i,L _|mTf6s;%e@ujIԚ GģI e9 $am']+8U0pbޟDslڑ7q{,L hy֥>&QtBJf=u&r6W*kQ=?ڬ($uMKdy-Kh93*ffJwh ;17-gxj+"T6FŲG[̷̥÷i{v T& mHSF>1cąȒ9)`o5Y~A/,|kk?]Fd,'xQpX(.%^n1zᔶ25TZ= I[k_ǀzH==+#}8Wo{zWEYM 18 θZfEk J8Y139o #Rb5qFr7ƻ-QuEw,o]i>0C{&?S =Nqߌ[PԟG-YUcjmh F3 D+s]j7o0E?6\%HUt>]X9 qPw=A~١!*wD1m .E*mn/ ΰ:̼X6 s8eh&o%KHn-8Wca%y-XYBt d ݻ͏ WV(ըlq+:iNO?IF.Ƒ%yw0iݴ,&)P,ԉݑp{$tdl-;Y8It<ΔU\/snsSUgRNR'ǂ$"Kl=\9HF0X9n)+$n|qCHPe%d;dI|L'JW-p=Hٙ#۸x+RWe|CG.%فNm^Wjw]ZGh[b9OR\G@{wIzdjON@iHe w &Y2W{;7cO4}󑚥 'X9Q79-}BjܫJ0QΦ[Kr5@Gv oNY=oJ視TM'cD^ϣj-:%>Up&IXZaVBKHI^٠bZ&(ᓤl6 DzRwLG0WEDҸ zGh:2" v.Ud*cS]cx|r(;5G4˔<*9n…\.>R<_]0m#wk"-ϹRI`i>0aB(Ke֓"%W1kyb>HP#If#y.́Q2͝IAl&v[~8TBty5[ѻz9&dg/NfX`F= m3B sMBj켯-mBGZKS]OYu4DyΫq-ѶHA"SG㣐끌62N}\D(Zٜh{ bɬa%){?^ xS쥩4 k&3le&4Se݅ {ilc+1_ XZڛ$OXg*@^͒+Y3} IS69yԀ`1QmS`K;ftYp7<2M+Gݩü89ƟC$˕-ʬq103AsԞN\ \nrGοZ0}SvnH% fsu)dN OQDksʐӗWx* jd9ŌD5RoEa#gMs{#돒-g!$]%A_:?vv>.`=(0[ S_p?!q:Rwk7Wʾydɫ;l솺Tz)DBeM ҞT:aR&",}H7Cf"sEa|!Ete 5,GjR[,ݳ}Og cqq q[ij Xef H-u4FDSǯ EKUNmY6׫>ځ0ا+ʤI΢H\]S2d%1y<\?< mAߎ:ߧQ̽c(O[&Wm0iN.s Y>w$n+kk\7;*jA+:˞3] sMg1[v*N#z팗[9zI3AW_6C?:q;d&>*&$Gԃd(xʋFE]D4ebTp~V}GmpR981^ybWlmgLNPZ >)X0׹tJ+(Vd+jw)R请oΠVG#cA7mw2BQRд}۷n/ *:Y#R-vү`mL]3Ur/4G@S|b&4G(< SK9'@k!- oLNfNOW-MY'Ka4"]+hLR#-L S߾n4[F #ߨ Pr_ 8҄%{TwD[ (_ǭS臃V*/n~w—+ @,;#LS5jI7I䊵1+D/^ 1|ݛzz X(qCg/QaWX_:R GVGruJ$+>qjͤXo>4 L1!>1@C6=L,`_GaZ0c޹LIUyDk*Ij#MF'ez0go]5l𦻃J@0?6iR_9갰[=[o ªx*N2>֣}>ΫU>'ىұ5A3PK491Qj7] r+zQJVΣ}zegj-d4EϘT{.X?JsZdNT,Y'.ԑ X&Uj2~+/C`9>d❞;`[5VŊݴR"X>'d}*<,Yش3$Yr:ݵ쭣9U$dn\Br=X;yhb^8JVxڟo@v+K7J+SM܎8TŒ]v&zQz No!yߕ7JynN7T'Uxlq̀|Ӄ 7K>7 WfG{HqX{B&QeC[(% udfxr7vKEs(Ypl HȟB%ȳrIQ)OYkza'OHtĢ4kԓ0,ܢ@lCY,a۴wX.#_ ΞTNb{e*8y'29q50y /OHU#z CPk#롔tbuĮ{dMTbmAT Pbr<` 0@@ 0W-ժ _sIO+ywώ׳u:b0>.j(`˭Kc?VggKtQ3Fj^Wmd3^pAS` 8~ tTcUcӕZSO|O2iZ·ax:I~4wRD?WSXh<HRpψtS-\H*|8bo WN?otD`)% a6++Sb\lŨ2s1ۇOD1(CLO%p$v' +zuT_O.ZXi?#_tt0MBwq2ְ$s.*IKfie6] xmY[HUT N)G18T]bَ8 7ƴA8QPX"g!rs%ޘ9)(B=gE_^jNpGנHC6`ELT` ffzD!d_0jdo'kẄZuU3:l8P(oḟ'> -wXz*qwvEkÍ,W}S`yXP45L 91J4;= ϾuW)Ј {Ljn>˨53 ZS|s E3J>R5GJb+z`#3tu9m`&hze:|?˓_ &v  ԫv˟=N  JxQB)-9Z=%3hބUja'M/[g>8W9ZS kv=]qK-F*Z@!ejgj}5{VpfӼ;<"$˔ȔpL1O](lPVdz*1T8(d~MI4{F,tvhhLįծSn_PSn-Ɍ;yƊgVF`Wib9;e'R=ɲRk]g=HWޝV(K/? uJZ4}YdCGjcK˟ªƩC vVE!$ yasH4 ZUa/LJoV׳^*WuOR|5 B39E uLsXxnE٩x=\bH+^T}k M}!qWDȐ7,u\ZP.yP8>7(3<j+/kvr 9$s-#гf`ʊ!v:%?t1 1Oﰇz/bHkߦ4Dꉉ--5ڭܯ@̓?2s HpJow[D$]vneٱa4&Q| ңkza:,7w^ҷBf.XNC` ԇ|hB}<=KVzڙA 8?EQK򱣚趾:.8l;ȲI@ ):-= VGūKFkN3Q0/ЄL [nuJ8Kzc‡ӦZeۃWxRXU">T!9J9 pڂNT'gZ2TCy('`n1>#19 bwm"k,7C79_9BɔY M-Y\ΦB^jVΰ f~X%>( 0cEHD?z,bo!Qfu4oxx&%]iۊ;x_Ԧ .$^B1BBNNLP#.wm^r֑z|g.n0AlH@cb0Pm`^6[fq:J?cJ.ŭ習wI%݅ ,l Bpܛ99oSƜs׆r@e0oi%L8mnr,b>b$'ץ~xQ N4ȡ)#رx!זSd:toҪ뽉@ m\TB,eU^~ >/&{*틜S vU9[k$&#@P\1+х9r8}֔5\g?=Wf1C;h{Fj,:Amp5Y2Ys2q:EF̞;d\ERY`Z{t[jlۡl"7k m ?y6Emy#T9ߦ9J$ "cw|vzg1"-H2cAL>?7)nɌBs.[A~wWWIFB-"2'wbR$9E% re]+1'A8ӊuoʋ.VRjO羿5cXHnx< Ԁi=~3s~^ypgB7S}Z7 ҚFC+82%-Tп$V5~VCNq W8#N)$+Lʡch@ s~UYzn1YޣלPd)+Yr|A\ ѝ_/S6yx8 ŕܴ@*u';*JBѕ޳4+?5~tڕv=TAnn Q פGiOlDgcMQ\˴漁.^_}M,7 @57ke\_rk =w} %`257s)QUzj f&ǎ@χ!"W+¦8(AOqe8ePm1Ӷ -ԍ\pY`]}Hi jT%k$o΀/Y`mrD]((inH#Z]ؕθ{i}r@ȹ`ܦ`7Wi"{i6`qIWxϿj`=^qoܬv|K\Iא7#jpY~ bD7H(>pm݉dх6{nzoeZආvM.f QL{6gho50SӺ6h =i_Ȳc!+fuHK&'oz3`*jƮ(Dc-Zc{;mAiڅ>d͊:rx7t}˥eJ#d1U5ш QOs ą=%y7d<Žfz_,;K)vH{3f\atC) |CHHTEܘ٠uLT%3(2>X$5d{(^¤%dэ\KsŃ9ƥw5 Li,һ ˥9$eWMݠ\XD P=>%S'uH?AL9FK[y:J>bqFMASNuw.ĽWȜ'0)cxZ?K*{>eJ3Uj5qxy.'v{Dpe)"1E^>ԋhZ;T m9ms.xBG=! 5 r4eS9^ (t2PٶvVY"]exa2.` =f.ROaLϻ:-E.LXS(QɹU_8s vJ3i]YA(ݦͼWˢd"̻n zF4q+W{p #K@o^mo)gi8|yqN2CJoc#+0o^s d'C ]Wri)X4TlgKtJ٤4@̤>kTa7VIBԁ&#,4tJyRЙj<훟/*g۩=?\56Faur,?ឿF+n\:] Zs^PHXԧeyoYTdۉ#jlwL4^JXmvD6J51= m@\>6):Xn'Dޫ*8{֧X?a$Bw6|멼&T#'ՙ b ;ȈB )WםY5UȰxIm5O¾F=6ګ5}ޡCN gLw?V:$GK{\m麘ȯ6cWd!̿L?[G||-gƴ_= TA0dZlxRe Rδqɮ /g =FO}):Y#1Iw]МZC4bE,$ۖ>pd/;$bv5#עnn[:jrR#D)?x\==䅝i]#5q׾[|Ww&D 9Y aFXV?9$GQY< 1'ܔ,7,gl*(0<]mo²+\NHP9Y|_\2t^7X^y*s/S\ǰmh݅'d>N qq$$oY1hDc}z)ؚU̓M%EU/TxŃh4 f ,TY=dPͺՕhN:))%;9fΤ8iB S@MI $,`a(.edyjV9Cq2D}j}҃~?\PPuKoc h[E_pp䢡m TF>ڞ9S'M2F+8Bx-:N/1oU ⰻ,[NFF:(@|DgY9OBX%IVZDo}hhyZ#KNHI`svD>\EaAF!Y (nsd|e]P|\Įu}Ø5o מT패4Rٙr^+ Τ 4b\* `7IԆ<oQ-us'd\~@)ygOndyu ƙ/' TVULBorX{6A W<Z![ORng#b܇Vr+"vWG(ؾn0.{/>S4(Y&@aQ a֥~e76$ek=qak~ LG~BPl [?iB5/d)pF8b /z H58!7uACb(qf о᠝be6Ns?9%PΜu3**e^kAupB[LB}<}>xPN Vs>c^byǤPѐEapf[gs7bCqZ4kҬI.KKg%L"(ҔOVs]>!!ڤ>=Ba4|bbR%a,`gܙ-=S/D*؊9*kwknBd< qLRC->T{V5[k7keb6+]ϙO*n\7+񾇡-cHJyZbZ}AA% ۀF_@i/0&kee\O %ڴD#s_*ƅMDj07 ,:EsX_3 <{Coޡ6$.x) Mdq2f|*:)X:`dE^Dw`4BjGu*py1*W<.&}b֩{ >ߑ2˒XK/2w2WyDk38:K [8hB/)jΉ% 0Me=G "B(8 P1yj6˓φrW^ 7S(kHفPZڸ Ma[M/]^e2tԨqm/3qJK ogR"jS.w‚uЋ[b5 KMy}DsyŲ B?&wt7ֺmce%h,nfv/n-Gؚȸvb* O嫗K2Qq^F(O& :8?>!Z>zohӎ @}T;vLU<>{pf+y$2,T R5>3TBlExCwFE&[b&p~8[wq#`TF6ys4khxك1rESg^Y>_*!b,q!꫐p.;Ik{xeZJ%<"M (H:af;/B`h M:nC6q򉒎3I&Epk5x߀x-= vm&Vʀ@ȇV?4u4rE}w?N_Ѡ2=-E^+ GJHJ1T~5'6!|Y_C"r Gն3ph"%RK!ڒȠg[e`>BP{di@eo-逼;{T<_̄'HrA%N:81,_K!O[ByNƧ+r5bD/|*~̶;O˚ԩحZkL";RE`Ѹ]Wq/rP{fA^[\QfZשrZȣ=A`D)>g_y1ʊZجp*#ʙҖ#M+٢޽ o=7n#jeZvG_EQPB%=;9/m]?^myߖ K F*›i-VђJLrIi!=.ƭV?E/Cw})Kyxz;ˆ8m?Z[ƈ<#/"Sk8&BX˿m].d &̃Z$H-fTJĞ5`0*lGTnM;CKp@lf]# NbE#K~4Z|JCpK'2Տ?z=bl"+H,"-y羔Rel Jn}{)gxNb2{>𑗰za׭KtlMv2qM> `Zc %wk!/'mau{_Cmm2 S%I}wҜAy$[LV%~ F`>JXP&Y(C+B/ҠK~NP1C\S y6rEX&tz@U^Ih+i\G2Z)N˺ljʘ^$-1pb[k)Z6>yjnqL\-|TGE(*T\ڎS֪?,`y[-Ł}k~d'vxf@*!bC8G[3X6Kۈei&8wv╣T:*'QmHs(K'G20\ºjP0nH,]|1]KDtj<7Ĕ%14mT˯Uvrׯ'{Dߝfd\P"k-Q&:*IZdBo߲ddžiZKC,~˩b<"u$/yNҩdRWC %YQ$#hW@QR JxDQz}BPZ%>ͅrX˔Љͩt!k;_ ʞ8Òy[vap2Oy^N:82>_yY V5OTi7*j~HGDI&0]mh H2c=;|O'P'~ror8K_ x -'>Yٝ yN NMj"#oOo,4$gDVN~s@$K?? \=8.TBK=9]BK#u*te]D?x`JoVa$"AOˡ[p+G(mBP%{*YD'xcqs%Ǣ )C-Lo[2Va4#nONvO~',: }_a&7pt~~doJ5؞%ln9G,'dVϵ$I )D$+x%X3t,7Asv)s|!{)fA04D@P6Cada'~ƞ:] zŤZ"cުC$-2Â|^o3)")XS+GjH@T1czT[9^>n1WDmW2n $Tmx}{YKQ]SEy4uϩ, f %top V}h6bVf'lWW. 'GJZ'ImU6GXQ`L<;+ [4vav ܏֟6F^5w( ɺwU{=Hyǻ6MK^ CQ`z](>2w16YW/å62ⳏ"Ԋ]pQEӅ X﷢J>}wwa)P ChaB0SzD*>4Ii`E" YrvxayRg <"ȼrǚ9-ULhHxc?xqsRw0BgCK!Ҝ]uY5Ny{$"W)@~(~.CB刮0ʔi:o:tXY֛mQ}p G€ժuB\ pS>` .Cϥ~NRa gQVؿKh# .~𮨍5yC7B,\mw[_%&Q^{hIBC"Gh4׻l%H˚Iƿ]X(]8jCqPx=v E\՝ U1Iz6s89H kMi$g Yg"?nGX8TM@YGXWPN Nxn $5&o0`GI xe&lȏ9Ht; r3ց%R,j6{!ӻ 8\dO+D{,w?`̛ˠe0Q 7T E&( [C_5q &i°*>pc\5dbi/趸I{yTnqǚPk~9`5kkkri-:g7D f%ʕ0L֪g߸`qР>rU kHz'S9qO#w[)תBo hG; :\!=o չ!L نf=;SMSPyCK~s|ń1j RA2f%P MGeȳiia{Fuo+CJ'&7pUF،sms[NK`e@J 1|B^m\)<ͅ9n8O < Sz̠Q_`D%KlK-P\(V&~*u+M#) N{)@a${ v׬8@hf&ә MU>}|aG𻅤D7aډG!=#o)Ћ6=aBl\ksPYTUp8<0 }-/VoQIyC":.mRwD~RBk-' )CdACm_ e説*Xr ӻ2 X/VtMҷd2Cd =VMS+^+K/ӂi 19ձ˄n8{yFo| kDhAaKWqD % _.,RL迟jֆR@Ulwjt%! 0Ss]p}WJ!Ȁy"5jSKQK] [>=ρ~XLA+J1% Uo'P6chD(:֪N9rif(6# ͝3|mGn2Ri}VZMĻƋ|^ amyzzq*,ϲHhn:m\*1P/Wģ#q@W.Osanv{ ݧQخ5Ҝ { MLIlZz֟B4ɴL!1%B77lz@'c@:t9J`n Т$/*ylZ8{\e+"[&dx*'=^I dEfsb8N 9 Db5BIU: LF9Tmp[Ҁl"NWy\O8v~ /!'HH};F C?7zجlgY12<_ x+?FƧhab(Qx_3E^C} h9vf#]vQL:8|'e{.XKoNSf;'-Lbf^M; ?3qOso(?$Y#CDy$o3(~N3hۓEf%z52g[*a8C)(>ָap`X ^9=DJV" I1]Xxkp ɌMa8+G^4.cMxa|{?$nUPV؜u͸״?HpUg;4]̸Vh*+#̗@C&|Yed,\81r9*B2b&ժ?Zȋm9ʋβח%Ʃ]!`s˷LfZpR +INi]*G?ćtv o5\ yemљ\LtPgБoJO>0%?y8 36\,9>$ LQ=wTg{QBI>~citZ{|;񳂃GxMOBPP@jDg JܵOAzy mdu9.eO kMGrQNCCMs.zpe;"?԰ аEZ_\Y:ۋ[d>՝=Wu Zn+.==uζ e`9چvU.^wY - T! ;*ֈЇϸ@QPBo*Q6? HZwV=u#\tDnu""(OUͣY?[ENm!EZEUn`SRB:mta0y0$X:##J*U"R?cGZن*@%,Aٺ}hK(7_6:͋re덴l~u;"Q8+ APC:I|paaG( ѢD H*|2nQeKayse]{5q[:Qr!tX~Du5؜/q3hN}h ,]UI !{PILG)ԥ  ͮ Okgti~RK0O-P!yy|bI:]]CQW=ݟZ۴pRb}|UUNu všUKS3t J 0)>@j̘@YΟ;_  |GHluBRG~z tZV\/,džV^j{BZwk0Y].@z6vcy^/'3;*Vl"JFU*c6GӼ\:gcү/+>3jˇȋ?-L< ..͵%l%M?_G L5E7Gjџj^8ٵXyD{i "1Mgw=.*@:v4$k`۽ZsL' L~wO0wcbNf?B^Ph8OBI){MCbMChQuuP;f^a)UirDJ)ӮP4 4:%#H__4J,>Z]I(T qgQ}Q_f[=-TBCpQziE$yQEܔ@ LR:< $!ĄƖKxi:근۹? gQj=$=($Ny!Au{Q,mXIazz:2O/2Z?3Ԣ(uvTQvi%[R5]JP}&m34E׭%gjl={q/<(Y]PsLa(I=Ǝ5?w+[94M!ʕa1+溵6m `)q8:6p5#rqx WIӓPOE =zN4ZQVS:E#ƪ1j6a-`[ߟDQ– 2KJt<ƅ~fϦw^Vh9T xu@KY˫)! ve;Z فgp{$g9 "A"s9Y0pj쪂E< U'X0j0oD`{_7a1T[Ӯg(]jX u ]ffz_5yxH8TNLy*UӁv[)_ _@{-hrb>7 &I4`Ȩb﹢OcqXRuP(JyC%sJ̬.6XNy&, l4ss!|dC 'p, *X^!.wz&+1-12+p+{/q`3Ί<ll=2gu/-IG %V_k{#eκ*l봧V[f=7S͑frIco_-E?<(dota7dͽji%Qf$4) SnBi+.fæ%ql-b@ a"̹uX AƇ3d/փLb7r@j(rޭF2(T};~.WGmhಃ{"u- 5/:x=ZM|{pCm VK&8WTUXٜA0~puaA@ۥqןcμ/x' Yc[_Pˀn=bz4;^q;6%\?Y.ÿ"{ >Q@_7z؛vUY^}م2Ի=V"Y9ٝ\Al! s، "?;c"V=wEk1'aDl԰r+>!xvuqDCs7fyҼ'p8QG0fئ4jĺ֙jkED1dz)jCGDGcd?CܶNz7$  ZM/Z@8MK8\]&}G5 (F Gڴjg6ߏi@)Y1,o9%ˎQi@*Up#HEڰZlc0e_~>>Ih>0H*S ,u6Vj30c#/zԹ> 쉒sn"Yɬ?a;8L<ӇjHcPRN.z)b`JԪ4E8TC{D,O`9@r"2X7Y&Kq'3kN5)rzYN4QuBC,}v8?1|ي= YHU@A|Zݶ]ڭbWrk~|6Ew\B;8*Jy`^w;LI咰ǥ\[!c*xso'4yAm՟10$HnZ{pj syfl~jh |@5!5X7FUW0MFYI%y^ݤ֣II÷PI)ܑ..^b׫ kS<8u|occ8zVf䏂H{`^'k2/@j0^Jr97N3NC=فx֡WE@48YTnK_j~͓&B"@Ib91db6>rsfĊmf+rIy~bbu\C,)J(xd0j.Vc,//~c:|?1=u1%n~) kZD> [ъskJzH%`g;43dQC "$r ۦ5=R (4`'ڈ2B6BkPy8iSStmDdZMp]+|]|^ly!wvZ{N4>5$tU#NluQqٕ-0]⯉~ ;9jo,{_R5+sպ}Fm;p 917M1n th#ѧghi)8a+~?ex4*]_Ů-]2od!W(|iIsR#8g$Zu] QlN 7\b u\ wX0܊ekj4Q+! 8pViJ@K{E2uGKB*)c ko+ĩ~qdfcQ|9ͨ;Oe&ti´-P%*9'e0eyTȳ j5a.15Κ> )Gj,Ct'6W1]ݩxMTR #>3+±g&E[L8SE6y'HϓԦs0W Ljk9 Q3!)Qiel,,%28L+IwKڌﺗ .01dEKUQ4gʌ=Uwb -"r6 _J+~O}Cj's>:^baIR{Kzb.R''gqx|YK$9&E@Gt)ޞfq56%RR=EJa(JJTI A4mgWO@5̠qNQDvK灏^NՁVbtٵt-ʏS4Fz:ܱ+'BOeQN;2&i7g?P-1,й_sgu)!?g49Ri l_b;'$OhܢPyӏ&#qK`,\/K﯂YZ"}ĝȾQe)fOT휈ZAA*cMbEc܇wG/g:kP!r!٨H{zBo sGE]s;Psn?b$ s_(DI^$ЙMeKᰒLP0ڔ\J5$4ض'Ҵ+BaxZ Iƿk|(G?kcd7nk\w4uŻ%dANj QSo]C夋ObhCB+0τ.722f]5uTM$ Mdʮ:9egO;gy|t -qW@]Iۚo/!xxyݾUow^q]薱[v9eԖۛ5n{C eٲ, y WvDĮ2165Ԁܒ+T13kc'ϼEibhh=+^4T*X ]B|DCfM GrSuF)-Xg] My7=N_hjYNO-şXSrա?Ƶ}A7A$Q`O䦟gZ;N)fݹnEW=M8C8>6UۨR0)8Be,;;- KJP}mSxZ rS5*N4kF7ƌ"D"pN9H ߎbjY"8wP :M OKxY 'DZXd6Nk6- {Q%RuK*1mUoZ6[5|༳ӣ6_$(omXRh?Z:7Zt[>YcTRWw yG6fȽ~I{0u饤'\`7OyPpi-ofAi;%}bߍ21X DZ(y0{:cV0Q AO%0|G@C?K~۞aKʦ[Z_~[g:5: {e_fhWX,hɕE2pwшv2q`ō6& 2xxv>31y8Sw䗧|vvhU-mDcɁP*Foٕ9bT I?5K8K(y& T2idRM0;ŀSG*B|c'׷u?(ڋYa:c5%va=%(r#1L4]9ƬF,Ep2_}5:NOtr|}t]sBGI5kpP .֮U#*~N~CL$eFSn_5l\!:SF{6H o1QKyJ[tM% +Ud:mIAI٢zB{WEwݫY7 P;|-^) =2PCAʘSZ`%`I&K'.IaXLfToC eݼe}b^èDx F?b4k-[y:Z|' /^h娴7. c^2)x=oeFU|G-kE{z˝DVQ9JS`+ ƎiHSԅњو2[ﳱſLXH;dkp:}|aH6atgN0F}ⅺk—Bl%9"FHfiwYn&M}Hm^[}m\䘼2#u(1VEpCܬ&Fԙ}jYq%JH9“Q?#D 4-32Qm)4-5˯~e,f/Svl"\2;J!_ɲ N3݋UoJyػ6_@pX6Bzb.̄ ;X'ŷoj;3!^7@$6 f'U9L Z;{\tE} I,E*)|'W.x}V]ScI}b)ʑPI1oiue< '4-A O^qO-WpޣQDsezpq:d8鎀6D^P*\NQ_>M 0{љ;'5@_BDn]E]n*v;R%Pvf۽U55'8$*E|}˪ z] ^majPBt/uMzm@Riם `1\K1B0p~uR<4fToİ:۸n;Ϲ,!R]?Bh jH*|H3F\C(kwF0wizPq7R]E[qTMe"\'˻Y>%.MiHn`? ॕ9p$\ZrhՃ%a^V#O_b2 xG%݊%, *, -z`zMf8Sw tE}81$ӎX֠Vs:}?R!w2Ix 9|S{PtD ~ܭ;GC< .MQ.-#{4.so 5HZ)L xiq\(1z:pzM>2o2Zsz%V3.sh1vyH4$@.#In&e‘1䆌RSeˀ`gUud\-)=>2<ʾMnw`WS3Dr"? 3|1Ps /IX8D-4uN\2وF%p'9A;FKt54(>- Bh8dQ 4 |AB~OHSߧ]Mȯ aK:Bno78Mkm9(7Bf&F#6~Rĺw?K^~~JHzU*? (nb6%]I:e?:% ׭dUazrB׳r' .eRzQe5ȗ#V'q y={lD$ubF՘K-z Y$螄kɦ7Fҟ碚|pWXAixV'~h}Ki1HK~di>  On6(PdpK-:d%9\Z.pu  JHM3YYɀiEM64V'%~D:o, X":' 9sDJd񞯘ob~w%qc-V{aK $@3\u30"YC pa O7mURd2j܁M¢=#zsE?SX3:+*~}pi Z}=j5go'6CqGgԣ/;y+i!& UrơT (9^틅5{ ~Gx\OנclrsęA=i1WJW?|6?*eaZ80<Sc~?aI?*#7=wїyi߽*p54DYᜈOgx1&mZnvLVb OڗiQZ*VfA{ quvPq8ϹJPE#lM 7lS¬ik>x0eȚ>ް<,01mC(˟ʓDyS s_Si9=i?!btjfƠ}WE)d9̾t14a(;P>cAI!O rsZiNvTng;ݫ8+Vx dfׇЗnpQ_cug?Q]qD)>iR j|;¬k^ ,,[X^y#\x\" BĴBkH 3AV Ď FM=ŧ<3J&ic kRѹ\Lu,-w7sߌ,K]gl2GuXLNY*E5? /i-G VxyODAt*=Ddp#(˹FRRь6 @྾B= 餲-a`k{b,ixMQ<q G5E$z [O6ra.OafO@%~. `%T,⊜ !9)cg.ubʁj٦ٗ ȕyơw%\E%fZDu&oKFtPut?Ai {Ȋe``!vM4]:=\SrZBy3_W]3Y;~h[phg2V=k>URrfM ?)J%tmOy;#bi@OI rZ*kC}ԂHx ij#eO>iWQא_JË9yҌ]^MUxF 73JNE_YOǥC֫}5He׀Cg< *K;~rZeaK҄?Vr(Qous=zאm/~#ctc7;S|rw^9 _]^^'Hˈ@}~7t!a.+Nû ]2U@2 pqH}ek@4t )mHxt\9SFdVc IE -mN)3&BDjks̓: xu7ww?]adE !a:1MV8yZ K{1@/ę%R#1VKYOs sn8.]HެM]W O˔璐 |@ߜvGRb 9;G0_,"p5XlV61Y kW> i/x[F( `Y0dn E 2 eb\-cl?ߤ?yɽgK y?~<@-[ʳh -(!E_ݻG/?DI%kӺroG o>B$:ʔfR+4:Yp}^'rfέjNhb⧊S)¦J5Ty 8jA"͟L +-trmч!E7yNB^^op"颻4sٝ%vD'( {6/J]X4C7!6~ъ C!2L)R#ҊQu!Ppod[1B9}VX> W1σ[NS{0ST׹ڴ,6b7: Wk0vU:POhUD)Hdp3o~G|x b{%- !cѷ`N-N|m#C͔}J?l2J%,oǑ՞?H7Ot$.>=ĸ@~а,6{Y[zZ S-`?ti:/ z#񙖟 YMO~kIbnֻ>}8kc_>QB+Qa!LH$}}P'N"&k$.=„ ^\.̃y7("d <ЗducK1.pĂ,77>aB./w"YX:Cۦ7֐׊!)='IY); ] L.w;/ }jB|vJ`Y`-|hCGXLu`SGIS\e4NdxNNoxͤ %Lϰޑ_JK0\ ?A2o淂S~y߀J%rҞ9._tj&:&FJEIK&V@ )͕3?4] B?vFp p+E]XEsQ Ύu&sǧ5W`c}Y4|GƄɂyv[4Xa2:_rfU@#/0w/c w5ҳF͙,Zm᤬gKm@sꢃk%ɺV Tg= a7Rtq'5WCq_BuH'yT3KGefqv)DQZ%{cyyEJg%zS^|^ 9Nɼ4nI5 AjRk!M#T:gyd'R7h7t9m^ q]D5AGTG6RVЀ@oƚv}]Ȗ4%Q>A؇S7E`#i} }Qi-3/ Zvmi>yBaz^hw~{Ʋ&}X?]5$=(CJ瘈uq@jN[n/V<{`BZ-详㊫J}-}-;@ҶJl2c^GSnKp蘡ƕ,4%psZ=`\ynG?3aomSI!I! p\huHۘFn[+phEjdxolQ ͺDXk8 HOIʕ]XvY:3U1#7%9'!d!ǵ# 5Bţg!G'r2fXry_{ jH-L:t8qZK<ߺdT)u`p1y[bzPʢRڶ7< &*A$-n@~@["lx9ZjpZnn8!-rH`2P&wwk1~UDt} 30h @fD?iH<P 0") =;}5 9K/,4vT|vtCL,y; MD5yVrjls˂"oLar?i{ppTP yx"KMklc|hl c'cE> ?U z0e5Λؼ"_ 8J7OM+ HVL\ /j_QĮxnu=+I6מ PQW Jxy{2M(o|d™VBFH]5xF6ߕ|J0eC$rCܥd*vip)njcCڭI#Ty e%Mr#ZiOͪ"rNPd4|ŠLkyRbwg볳r68X%pzBٶ>< sYdЕ`ԚʘE/,'vF@ 3t=h},>W.5AђBm-9(<䫎!*쒴Z K^7zh&_'s֠ZyC/DCs`G]RɁU@Ft 8f( 7γQ >]+I 4KE ՅyoCZbKjI2Mԝ0}C/Bc.3G3= ³ztI4>ϳӺl vWKun'7ȊO@^;B_\ҝ*c۶ Bu{PCy%T$Ȇ+rMu拯a/"_S}$k {kx~k;#g zպǕf+2mX`U/542^T'TxxnXwFeH;Qw{ y'k4]QdEc)% Y,g0즬tzskvV7O"\]L*lm9oy ӣ$?5IrD:kEcs^^cr(e|nlҁP1ה6BJ/ jI{p( PzFJhkhl~x#=cIٺkROF)rrz ]aYCy.F2jSB=¸DwHtx-m.$ǀ|1 9^xVߵ\R3LY3'~jrv$ryҜ:CV4Ҧr o_K5HN(VE ~B(jѺ)Te y%*)D& EsKg8(٨#'~mgg0erM%v>^w Ie~D`4j" NZYQrETL)k/9%u%}׀=¡[瀭YQ/]{ka/UL' ; WӺ FqW{AO> ?]ze W!/&r4AB &14Qׁ)Y:bqy%iU264 K'l!rMSn?&hoYGY)n*n.jB5D4ɢHWC߶QmA X9 wv g HTT梔G7Sr}7/]c*&پF.5Vi:A(s&]КU0 t@ŧjE̗ 0-\@BNF\~}i $`@]o8pl؇dM/Y}Eیɑ.:ܖH;1H\7 $UesJDFB"VJŶ9>ՎqsмBA-4s۷ko>v4饞p, >(|;APA=F-eJ:q>L`BmE! s6eA&c5nV8w/fLkCÇroQ3 sE|ܺQuFo`S4[f8Nг<?z%< )j[ D @^l'NJz}_/z= jf[ $$>gz?i!^'][ʵRFD\3NTH3"s/si+E.ʂ|Z>1$)gkx<8j3K#ћNrQOgQR~FVx\aqa =YvMp^LW!0&`Zl%נ^AS@ﶶ-ƛ' }K ҅DAMh՜aJ%?0 afg9o<n0ΉqtIЍ(FT􂇚N88i,<7OA[,h~LBf^[T)1YP61>pXKpm.nwӍuR%m[Vz슨[CH%˘iyUtC^dvD4S V%:/裰/ZʜFAcC?WoꊚG&Ff7p;6DKM JUPpvZdkPn+dq#k.~RV69 )Xjpp_#67નrXZ93E[%jZ+oWH=jv EKƼt⫈n*GDBc9 췑+ W9x /uw(.QFtuL_/>yZF0gX:%=Tp3/@fVBuP^`DiI'q'kNL0%?W=J^ bR??w5ɷޯ^gX3tVb+%>btzKk=f+g4cb6)'HIIhЮN 6sjӘ-;!"jcz@TL^8Mkqe#?[-yG,v5v*ϰjZǧ/B49Me05":%ODK7nؽ5#-IGƴ<'rǐ[Aaŝ~4/.t&Pl"VN>BrޒR ҒK}G*@`zj?N+CxHO$q1*}ltsSS@5ąx)o0 @lt15;mdrmmz sTKELyd0t,Vjd6PPͣDT|(~9?5ߘ5nR2Ru\:԰U6b igаb5uglDSPYæ[HmNS:zFqة^]hRaz]E ú(HNhh6 qC1m0(JNu/\wwi-—*bGoԀ|QNy@DiCDj2@çe74LW3~̥*Eţ?U&d dtٽ<jZI/kEM1h%MW~#P#r(\%p'eT#%?jszsjk`.KGC){PMEp:F\NJ5>L'鑳-8ԺYUJ 6 6C9:z9ٗ 6ܴԔk7(Y%Mؚ&ѯshL[(1ɷ0FN`.lEuTʩà2k_g#+*-`Kd9骭 r;F^#UDld;#sed̓M*i0$*KILRƒֲclrU0j5_ޗ[Jmw Ϸ c{G{>L`t ;Y;|VvogEgd m?`L5Fe눲X}xYB$IӟąƑD'.qo՞1'G)#1: +'(J3t/O=UZ\f3AFqn%A jA~eDa pyUfF|4ڡ{*ztEtxn~ 6m @"?0w|yEIG}nkZz)q2AdeGvAvOלA 2}|7gc c*7fa)hh]vH;g.]$- 2jc+8U]crBJr?k ՚χ կ:9 Ҏb~2]ITڷ_O@L(I #G_O=rai(0=t8h,ʚѩy0"ƃUj8[Z+d<he@R36xTL@Sr.awmUt) oVw L`T6\rЙWiP+VHS4h,Wp\Kvd?tq+SIޗp3f!DoxQhp)At@> Gd &H5c |w!(]dܝ[>eQ@3*Vn'e-rS/e~kD~9q7,gZt_ͳq(<)ld?n;˯.,[2[qmQH(t;rS>:l O6`0#.t +h95rv{ґ [lT%ӉDbiF/JAͿ8.B6\}YX4kơHNryn գYZ1tmHz$Ձ70U `oߢypycn "+/ y& ;EK*b}cMo (JS i$ P9O _Qe5T,+FS^<0Z:| h-ޕ `RN/ّ)/^H*fЬr@Ms8ie`簺R[H?6ߒ ٭L7(1ΡWs]|0c %M OMl `a*ʊ ǺYī 79.WÏd )\KފG+TNIITWI+{?d&9UPsY e9 {(%?7rtg;Sl8j{w!t_Oŏ[BBl^@X5M kpw 9 vx ;rSLJ7&=ϒw熤%Á.qgr^ΡN.e&Mh*U|nh mm0`X##8 B 퇣$0$+3,.J!.O.O\ O>@ i-a_^{g3ߵ$< +mgwT̺B̵ĻnhVsޗK? #߃hOetJIjXDiWIK,gf4aǠ+O3i.k8P Qٟb=_8l|I^}k rqm IƧ2^[X j@>@qUJpIt <|.k8dxEZ$Իn%Ta Oe Gƅ\k8:tHh *I ֔HߞqpG$T6z汳?-[[g*t_)ޒ )`FH̤ >J y |p`_;-خdp5oW7TڧuhW$I$5w‶1[!{8CC)³bk*Un)lnFG jb:4fxC:"j̴jk9LLv TQ_GxZTΟBI#~>^?QEP7nF:&qG m^/!2nX n{duR#A0q=h#laKkn%dl&(.y#?leԞ%k$!LqD8ΡX>bը'sɰHںq-NW]{+0X`T8 KaIfc trGC0H<ؼa}){\L%IUV߆ =ԐUN꿀$햱Eybeuv1{X'u@Fw) /qhFMhþPZg.9Wx:v8LL˙3Uttԩ0j %(7` 'xo+C5-E! y AiVOҊr<-T4XL>%/ =b.˿g.P>%Dx-p< Ϩ)PӜCcI;f|\žTߍ)\D#}%ZV^IAIWk79PZđg/REp.:)> g/EB,H bXM^]ۡ:H&:-pf ɞi,ӺFGszb3g;7;g[.Va.v:4=<*LMr)k9UFprl;ldz7)?ʔDi\VýK0Vs/B|j4 n޵YSVG'Ix E tcG~rxXzv{H yEoڵUb6$FuL1V-8[\\k<ңBf F+.ٲʚK;`T_3F|'z-JtVS2҆ñkܗNʠ6.(%U[CU4;kLTyxjmdlp{еZ!+ώ>ճ DҏҠ(F}k0fHΎ8^[;() bP`0;~mspu@ŭɌ-#g݆ O£6Uw:,OeOwyVegyږ\%գ{:C;9YdC V9y2Ǎ{aC KqHC$x{xtzj2JË jZm4`[n !h;yv[)/& T#"rSLzMU 8Vr%yl4oPºի/_ۦ,.yaNS1PB U$qsS &Tڤ a9?J捿C RōV{ͼo!\S"#s"N/~vEkk?g wLee*r/ UgW4G={R`m۔Œ=>TycߡAo̩ruic; O!T9jY%Z7lŷ**;P]Q Q=8,u)e=ij⣜ͥP _7QgChPH7L{͗,\myҸq{2&WӚvMyN؛EmΎY9| 'ܰ\_vX2SžΪAU:(r< {Hw\bV?gy$ (3Sy(a0}AH ת?okQNieCfF,R^a5ZžddGd!@5ómck  '09Yw$JnHyh$ (CgC$Z{0IF:iG6ob |d ԉ>IH)c&_`[4f}I3Дe_~p:NZ!$ @fHUcb_N),+;. 5e ?WZoL d9dr[ReE'.rh :v}Ro{Frc OUг} AQ|?uk3c}ꤶ!?[м{bJՀnl:nl6-E>u:p 10Dl늙F9bTL`tkKQ{Qc%}[բ~71J%l1 `ӹ<&4ܵr2Ԟa:=cŵێ^oO+gYOXkhY+'Cp yD c7c~:!DeQɟhqv^e>E?›UBVBk-FTux|j.G1.ƼVB19ַeZ1Θ(r nZnv#ErUk=&!$Ѷ$%X+ Z}gq.N-w:M{ 2%9jGpcm0%Oy$ĬAĚ0AS~nD찍&D%w<h範A(; /k";َ6{m_Df~H #\(<&gDhf M z"mxMbbV !uәn,%rsW_5gt \:9? 1d~> ۊF6VNlI\OL]* !xHy]̜P[>Brb0y¢W 3򺫒?ވuVVuhJ%d qs٫8[(H[ *Wuu=.Cxp8m%il JNrWq.!"ukvb(^8 _ŠcGcOC9Q\č_Z]'ջFD~I% rn"Xv4`UrkdYF}W]<'N\pM?{ZJu NI#qR0l}b: ~iT*)d7z!v!$'(Dž490#BАi)Ͼme:"lwE?؂9H\Ct˧ ˜oo_z<=~Qȼ/˵a}{-7< .7s?s9*0+J4GR x߽tQ rwcvM_ 4r~J:cEq: bk甦?+hٗҴCrLJғwhƷ;݂ ~qgä'l5Z3RN[Pf; 529|@rm%H