sssd-kcm-2.9.4-2.el8 >  H   ,0e U]BzTRgnX/c4݄‹X%4J%jUaQ-4 N+L[R!x4gJT)gI|315090afdd0acb28c8d0d2ff4b39ff6f8b4078edf9fcc769aa9aba62b1ae66030a0bbc7d950f21c241586b8175ed1b64664259450302047c435bb500673065023100e71f3d08e943403130aa085a1ce46cff569cb2754aad2fa82f320d355e40e68f08211823cfda1fc46dd8276c989c7c4302306f6b2c2c3e7661b8adf725a1d87823947a3a68cb722788c49cccace0521c18905eeadaf75d2f8e6d4c049efbfcf755e40302047c435bb500673065023100d7823fe9107320fbe6fded4b2916a32fc75ca2431c6f4fdbdb0c19af4a7bcc35bc5c009feaca4aebde77347df6a1552d0230128830ab81d4bf81f049925701efa8bcf596c102fd589986e3a59c9b4d9a4f849a58a6207dc8556c80f6706124c63eca0302047c435bb500673065023100d7823fe9107320fbe6fded4b2916a32fc75ca2431c6f4fdbdb0c19af4a7bcc35bc5c009feaca4aebde77347df6a1552d0230128830ab81d4bf81f049925701efa8bcf596c102fd589986e3a59c9b4d9a4f849a58a6207dc8556c80f6706124c63eca0302047c435bb500673065023100d7823fe9107320fbe6fded4b2916a32fc75ca2431c6f4fdbdb0c19af4a7bcc35bc5c009feaca4aebde77347df6a1552d0230128830ab81d4bf81f049925701efa8bcf596c102fd589986e3a59c9b4d9a4f849a58a6207dc8556c80f6706124c63eca0302047c435bb500673065023100dd124c7dd4f9710d9a3699735821f414bf4251c98c0359bc3aa19716d85975bbf8a2affacb82c6a3c5de1a6af5625c2f02300858dc537672a56b42e7c68c95a16731dce5b14f138c025bfd5961639003f7a40e614b975c9080aa858ab1600e0438cc0302047c435bb500683066023100caac7f8f2f19ddbe8e4124cc42815507cddbdcbc899b03606a04ced2ebe1773b98e7d150933ee4eb81c760f6366b438e023100e88daba29284b618863934bc82bfb87d746fda219eed247a4d717af3a0dbf935f55f069758c83f768a64d206f1374beb0302047c435bb500683066023100ede2110a262d0fc703eba905993444343b7fbece361983c6d80bd08faa55b173492910232b3c03acf7291275e2de56f2023100905b35dd0c52f2dec4723ad79c15d6110124b3e02d77a693a2d0121978bf65dc9875a3a08e1d863392d340eb701b8bbb0302047c435bb50067306502300858bb27630b3a86cb6165c9ec5d30f117abc8502b73242e4e79f9ffef77e33d141bf002fc4600c1fcab0d619aa42364023100d943940d95b3da3dceb916f58b9f887d54b76113b0198d2c8966789b3982817ff78e82e02627086f6989a2b3b19dc6ee0302047c435bb500673065023100fe2e22d60c6e2adeb13a38fd9610c6f71f5ddfedb7828c8a62c4fd3e994a8b74cefa3a3fa2b4adf78f494b8535235f0002305ad54c57420941c1e62792ba65e68a5cd77729146a8714189e57bd991ee55cffda30f9f823d9ee9bf571bc3c4bdaab5a0302047c435bb50067306502301677f1a55d6d7be54512b0050119c2040f1ca9306638fba6d8c8cb8e86308c7b770aaa9ce112dfe78d06fb0d4f30e059023100c94d01df228388ab56789d0a8bebbb8b9eedb1bcbce5e5e9bbe5804df134e6c9c4b374df300a609aaf46abaf92ccdcee0302047c435bb500663064023059483e05655267c8e8223900383ae094bf7e799afde44d74c31a13da669195320bd6d742662ae01e62b8d2fe81a10f0202307cebabaa42f53385f4d02de967ceff926d1ad870bc5f34a3355f9bebb29166ef930ae340a3a2e3e942c2e786f70f93230302047c435bb500673065023100d7823fe9107320fbe6fded4b2916a32fc75ca2431c6f4fdbdb0c19af4a7bcc35bc5c009feaca4aebde77347df6a1552d0230128830ab81d4bf81f049925701efa8bcf596c102fd589986e3a59c9b4d9a4f849a58a6207dc8556c80f6706124c63eca0302047c435bb500673065023100e71f3d08e943403130aa085a1ce46cff569cb2754aad2fa82f320d355e40e68f08211823cfda1fc46dd8276c989c7c4302306f6b2c2c3e7661b8adf725a1d87823947a3a68cb722788c49cccace0521c18905eeadaf75d2f8e6d4c049efbfcf755e4e U]W|I[]vdv@Ez;xȁxET( aH +$x.=0b/{C-nn,ɁD R-Q*ۡdx)4tjȎ\h[m@XBױBu$dTK<utT* C$w6C?qtLYYjr.d؈Jvo XyMHSdr_h Z'틂$+HU9AY/QFV~]jYH*AC9@ Y 1?X]tN"gq󵋘hEPhI-Ր2~l6 HJd& ?_XV ǿyr;w [7x Gb i# ZE*s^dƌ6FlN*v DU=2ҕ̔ muXqt<5M}gt{o?`9B>yg.iED>`B?d   B 9?F[l         U     >X ==h=(89:i">?@ G HH I| XY\ ] ^ bdeflt uP vwP x y0x|Csssd-kcm2.9.42.el8An implementation of a Kerberos KCM serverAn implementation of a Kerberos KCM server. Use this package if you want to use the KCM: Kerberos credentials cache.ex86-03.stream.rdu2.redhat.com CentOSCentOSGPLv3+builder@centos.orgApplications/Systemhttps://github.com/SSSD/sssdlinuxx86_64 if [ $1 -eq 1 ] ; then # Initial installation systemctl --no-reload preset sssd-kcm.socket &>/dev/null || : fi if [ $1 -eq 0 ] ; then # Package removal, not upgrade systemctl --no-reload disable --now sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.socket &>/dev/null || : fi if [ $1 -ge 1 ] ; then # Package upgrade, not uninstall systemctl try-restart sssd-kcm.service &>/dev/null || : fi%( ځAA큤A큤eyeeeeyeye|epepepepevevacfc8b31ea1b1931377b6c6c0f3541e0617be0a9e24769d5e1f32689120c0d6bbbac31b33f419589e342f20381138c0dea737fa71b0d67a0db97020b4451afd8c2f6ae53e988971d19b13a2104ead7d8f059bf8e7097a1a5d82ccb81764fd47959af3cd0923e629aaf8f8816af6a3956ef0d6f4db3972b747efb4ae5f495a2702d3b3e2e74812d889cd0e4a8c1f2971e0cdfde1284e5f67ee8fadcbd5509083b44bd648cf46f1b905486e147cddeca2dc8dabdb0dbe16cbe21b5704e11662c5f38f3dc983295fe47ef9a481ec58e320d309049cf1e76c49f3da3c7453ec26b91e76481a8b8e49c5ab94db2b842f6c3ba5e7986ff859e398b12b7608dec7fc98facfc8b31ea1b1931377b6c6c0f3541e0617be0a9e24769d5e1f32689120c0d6b../../../../usr/libexec/sssd/sssd_kcmrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.9.4-2.el8.src.rpmconfig(sssd-kcm)sssd-kcmsssd-kcm(x86-64)  @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @/bin/sh/bin/sh/bin/shconfig(sssd-kcm)krb5-libslibbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.28)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.4)(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libdl.so.2(GLIBC_2.2.5)(64bit)libini_config.so.5()(64bit)libk5crypto.so.3()(64bit)libkrb5.so.3()(64bit)libkrb5.so.3(krb5_3_MIT)(64bit)libldb.so.2()(64bit)libldb.so.2(LDB_0.9.10)(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_iface.so()(64bit)libsss_sbus.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libsystemd.so.0(LIBSYSTEMD_209)(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtdb.so.1(TDB_1.2.1)(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.15.0)(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)libunistring.so.2()(64bit)libuuid.so.1()(64bit)libuuid.so.1(UUID_1.0)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssd-commonsystemdsystemdsystemd2.9.4-2.el81.18.2-113.0.4-14.6.0-14.0-15.2-12.9.4-2.el84.14.3e@e{@eReRd@dd@du@doMdbc&@cR@c|c_cc@bbγba@baZ@a6aɪa@aKa@`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.9.4-2Alexey Tikhonov - 2.9.4-1Alexey Tikhonov - 2.9.3-2Alexey Tikhonov - 2.9.3-1Alexey Tikhonov - 2.9.2-1Alexey Tikhonov - 2.9.1-2Alexey Tikhonov - 2.9.1-1Alexey Tikhonov - 2.9.0-4Alexey Tikhonov - 2.9.0-3Alexey Tikhonov - 2.9.0-1Alexey Tikhonov - 2.8.2-2Alexey Tikhonov - 2.8.2-1Alexey Tikhonov - 2.8.1-1Alexey Tikhonov - 2.7.3-5Alexey Tikhonov - 2.7.3-4Alexey Tikhonov - 2.7.3-3Alexey Tikhonov - 2.7.3-2Alexey Tikhonov - 2.7.3-1Alexey Tikhonov - 2.7.2-1Alexey Tikhonov - 2.7.0-2Alexey Tikhonov - 2.6.2-3Alexey Tikhonov - 2.6.2-2Alexey Tikhonov - 2.6.2-1Alexey Tikhonov - 2.6.1-2Alexey Tikhonov - 2.6.1-1Alexey Tikhonov - 2.5.2-2Alexey Tikhonov - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: RHEL-25064 - AD users are unable to log in due to case sensitivity of user because the domain is found as an alias to the email address. [rhel-8] - Resolves: RHEL-25066 - gdm smartcard login fails with sssd-2.9.3 in case of multiple identities [rhel-8] - Resolves: RHEL-25065 - ssh pubkey stored in ldap/AD no longer works to authenticate via sssd [rhel-8]- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-1680 - auto_private_groups does not create cache in IPA server SSSD cache - Resolves: RHEL-10092 - logfile rotation for sssd_kcm not working properly, sssd_kcm never receives a 'kill -HUP' - Resolves: RHEL-17495 - New sssd.conf seems not to be backwards compatible (wrt SmartCard auth of local users using 'files provider') - Resolves: RHEL-18431 - Excessive logging to sssd_nss and sssd_be in multi-domain AD forest - Resolves: RHEL-5033 - Incorrect IdM product name in man sssd.conf - Resolves: RHEL-15368 - SSSD GPO lacks group resolution on hosts [rhel-8] - Resolves: RHEL-10721 - very bad performance when requesting service tickets - Resolves: RHEL-19011 - Invalid handling groups from child domain - Resolves: RHEL-19949 - latest sssd breaks logging in via XDMCP for LDAP/Kerberos users [rhel-8]- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: RHEL-14070 - sssd-2.9.2-1.el8 breaks smart card authentication - Resolves: RHEL-3665 - Unexplainable error "Unable to find primary gid [2]: No such file or directory" when SSSD performs lookup for an AD user- Resolves: RHEL-2630 - Rebase SSSD for RHEL 8.10 - Resolves: rhbz#2226021 - dbus and crond getting terminated with SIGBUS in sss_client code - Resolves: rhbz#2237253 - SSSD runs multiples lookup search for each NFS request (SBUS req chaining stopped working in sssd-2.7)- Resolves: rhbz#2149241 - [sssd] SSSD enters failed state after heavy load in the system- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2196521 - [RHEL8] sssd : AD user login problem when modify ldap_user_name= name and restricted by GPO Policy - Resolves: rhbz#2195919 - sssd-be tends to run out of system resources, hitting the maximum number of open files - Resolves: rhbz#2192708 - [RHEL8] [sssd] User lookup on IPA client fails with 's2n get_fqlist request failed' - Resolves: rhbz#2139467 - [RHEL8] sssd attempts LDAP password modify extended op after BIND failure - Resolves: rhbz#2054825 - sssd_be segfault at 0 ip 00007f16b5fcab7e sp 00007fffc1cc0988 error 4 in libc-2.28.so[7f16b5e72000+1bc000] - Resolves: rhbz#2189583 - [sssd] RHEL 8.9 Tier 0 Localization - Resolves: rhbz#2170720 - [RHEL8] When adding attributes in sssd.conf that we have already, the cross-forest query just stop working - Resolves: rhbz#2096183 - BE_REQ_USER_AND_GROUP LDAP search filter can inadvertently catch multiple overrides - Resolves: rhbz#2151450 - [RHEL8] SSSD missing group membership when evaluating GPO policy with 'auto_private_groups = true'- Related: rhbz#2190417 - Rebase Samba to the latest 4.18.x release Rebuild against rebased Samba libs- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9- Resolves: rhbz#2167836 - Rebase SSSD for RHEL 8.9 - Resolves: rhbz#2101489 - [sssd] Auth fails if client cannot speak to forest root domain (ldap_sasl_interactive_bind_s failed) - Resolves: rhbz#2143925 - kinit switches KCM away from the newly issued ticket - Resolves: rhbz#2151403 - AD user is not found on IPA client after upgrading to RHEL8.7 - Resolves: rhbz#2164805 - man page entry should make clear that a nested group needs a name - Resolves: rhbz#2170484 - Unable to lookup AD user from child domain (or "make filtering of the domains more configurable") - Resolves: rhbz#2180981 - sss allows extraneous @ characters prefixed to username #- Resolves: rhbz#2149091 - Update to sssd-2.7.3-4.el8_7.1.x86_64 resulted in "Request to sssd failed. Device or resource busy"- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2136701 - Lower the severity of the log message for SSSD so that it is not shown at the default debug level. - Resolves: rhbz#2139760 - [sssd] RHEL 8.8 Tier 0 Localization - Resolves: rhbz#2139865 - Analyzer: Optimize and remove duplicate messages in verbose list - Resolves: rhbz#2142795 - SSSD: `sssctl analyze` command shouldn't require 'root' privileged - Resolves: rhbz#2144491 - UPN check cannot be disabled explicitly but requires krb5_validate = false' as a work-around - Resolves: rhbz#2150357 - Smart Card auth does not work with p11_uri (with-smartcard-required)- Resolves: rhbz#2127511 - Rebase SSSD for RHEL 8.8 - Resolves: rhbz#2144581 - [RFE] provide dbus method to find users by attr - Resolves: rhbz#2144579 - sssd timezone issues sudonotafter - Resolves: rhbz#2144519 - [RFE] SSSD does not support to change the user’s password when option ldap_pwd_policy equals to shadow in sssd.conf file - Resolves: rhbz#2127822 - Cannot SSH with AD user to ipa-client (`krb5_validate` and `pac_check` settings conflict) - Resolves: rhbz#2111393 - authenticating against external IdP services okta (native app) with OAuth client secret failed- Related: rhbz#2132051 - Rebase Samba to the the latest 4.17.x release Rebuild against Samba rebase.- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8- Resolves: rhbz#2116395 - NFS krb5 mount failed as "access denied" after test accessing a same file on krb5 nfs mount with multiple uids simultaneously since sssd-2.7.3-1.el8 - Resolves: rhbz#2119726 - sssctl analyze --logdir option requires sssd to be configured - Resolves: rhbz#2120669 - Incorrect request ID tracking from responder to backend- Resolves: rhbz#2116488 - virsh command will hang after the host run several auto test cases - Resolves: rhbz#2116486 - [regression] sssctl analyze fails to parse PAM related sssd logs - Resolves: rhbz#2116487 - cache_req_data_set_hybrid_lookup: cache_req_data should never be NULL- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2063016 - [sssd] RHEL 8.7 Tier 0 Localization- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2098620 - sdap_nested_group_deref_direct_process() triggers internal watchdog for large data sets - Resolves: rhbz#2098619 - [Improvement] add SSSD support for more than one CRL PEM file name with parameters certificate_verification and crl_file - Resolves: rhbz#2088817 - pam_sss_gss ceased to work after upgrade to 8.6 - Resolves: rhbz#2098616 - Add idp authentication indicator in man page of sssd.conf - Resolves: rhbz#2056035 - 'getent hosts' not return hosts if they have more than one CN in LDAP - Resolves: rhbz#2098615 - Regression "Missing internal domain data." when setting ad_domain to incorrect - Resolves: rhbz#2098617 - Harden kerberos ticket validation - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol- Resolves: rhbz#2069379 - Rebase SSSD for RHEL 8.7 - Resolves: rhbz#2026799 - SSSD authenticating to LDAP with obfuscated password produces Invalid authtoken type message causing sssd_be to go offline (cross inter_ference of different provider plugins options) - Resolves: rhbz#2033347 - sssd error triggers backtrace : [write_krb5info_file_from_fo_server] (0x0020): [RID#73501] There is no server that can be written into kdc info file. - Resolves: rhbz#2056483 - [RFE] Add sssd internal krb5 plugin for authentication against external IdP via OAuth2 - Resolves: rhbz#2062689 - [Improvement] Add user and group version of sss_nss_getorigbyname() - Resolves: rhbz#2065692 - [RHEL8] Ship new sub-package called sssd-idp into sssd - Resolves: rhbz#2072050 - sssd_nss exiting (due to missing 'sssd' local user) making SSSD service to restart in a loop - Resolves: rhbz#2072931 - Use right sdap_domain in ad_domain_info_send - Resolves: rhbz#2087088 - sssd does not enforce smartcard auth for kde screen locker - Resolves: rhbz#2087744 - Unable to lookup AD user if the AD group contains '@' symbol - Resolves: rhbz#2087745 - 2FA prompting setting ineffective - Resolves: rhbz#2087746 - sssd fails GPO-based access if AD have setup with Japanese language- Resolves: rhbz#2039892 - 2.6.2 regression: Daemon crashes when resolving AD user names - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#2035245 - AD Domain in the AD Forest Missing after sssd latest update - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files (additional patch)- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#2013260 - [RHEL8] Add ability to parse child log files - Resolves: rhbz#2030386 - sssd-kcm has requirement on krb5 symbol "krb5_unmarshal_credentials" only available in latest RHEL8.5 krb5 libraries - Resolves: rhbz#1859315 - sssd does not use kerberos port that is set. - Resolves: rhbz#1961182 - Passwordless (GSSAPI) SSH not working due to missing "includedir /var/lib/sss/pubconf/krb5.include.d" directive in /etc/krb5.conf - Resolves: rhbz#2008829 - sssd_be segfault due to empty forest root name - Resolves: rhbz#2012263 - pam responder does not call initgroups to refresh the user entry - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012327 - Groups are missing while performing id lookup as SSSD switching to offline mode due to the wrong domain name in the ldap-pings(netlogon). - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013259 - [RHEL8] Add tevent chain ID logic into responders - Resolves: rhbz#2017301 - [sssd] RHEL 8.6 Tier 0 Localization- Rebuild due to rhbz#2013596 - Rebase Samba to the the latest 4.15.x release- Resolves: rhbz#2011216 - Rebase SSSD for RHEL 8.6 - Resolves: rhbz#1968340 - 'exclude_groups' option provided in SSSD for session recording (tlog) doesn't work as expected - Resolves: rhbz#1952569 - SSSD should use "hidden" temporary file in its krb locator - Resolves: rhbz#1917970 - proxy provider: secondary group is showing in sssd cache after group is removed - Resolves: rhbz#1636002 - socket-activated services start as the sssd user and then are unable to read the confdb - Resolves: rhbz#2021196 - Make backtrace less "chatty" (avoid duplicate backtraces) - Resolves: rhbz#2018432 - 2.5.x based SSSD adds more AD domains than it should based on the configuration file (not trusted and from a different forest) - Resolves: rhbz#2015070 - Consistency in defaults between OpenSSH and SSSD - Resolves: rhbz#2013297 - disabled root ad domain causes subdomains to be marked offline - Resolves: rhbz#2013294 - Lookup with fully-qualified name does not work with 'cache_first = True' - Resolves: rhbz#2013218 - autofs lookups for unknown mounts are delayed for 50s - Resolves: rhbz#2013028 - [RFE] Health and Support Analyzer: Add sssctl sub-command to select and display a single request from the logs - Resolves: rhbz#2013024 - Add support for CKM_RSA_PKCS in smart card authentication. - Resolves: rhbz#2013006 - [RFE] support subid ranges managed by FreeIPA - Resolves: rhbz#2012308 - Add client certificate validation D-Bus API - Resolves: rhbz#2012122 - tps tests fail with cross dependency on sssd debuginfo package: removal of 'sssd-libwbclient-debuginfo' is missing- Resolves: rhbz#1975169 - EMBARGOED CVE-2021-3621 sssd: shell command injection in sssctl [rhel-8] - Resolves: rhbz#1962042 - [sssd] RHEL 8.5 Tier 0 Localization- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)/bin/sh/bin/sh/bin/sh rusvuk2.9.4-2.el82.9.4-2.el82.9.4-2.el8 kcm_default_ccache.build-ide0f32d5b3dcde078710aebbc32fb087b6dc4cdf6sssd-kcm.servicesssd-kcm.socketsssd_kcmsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcm.8.gzsssd-kcmkcm_default_ccache/etc/krb5.conf.d//usr/lib//usr/lib/.build-id//usr/lib/.build-id/e0//usr/lib/systemd/system//usr/libexec/sssd//usr/share/man/man8//usr/share/man/ru/man8//usr/share/man/sv/man8//usr/share/man/uk/man8//usr/share//usr/share/sssd-kcm/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpioxz2x86_64-redhat-linux-gnuASCII textdirectoryELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 3.2.0, BuildID[sha1]=e0f32d5b3dcde078710aebbc32fb087b6dc4cdf6, strippedtroff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)0R-R)R3RRRRRR+R R RR R RR/R0RRRRR2R'RRRR R,RRRRR R!R#R"RR$R(R%R&RR.R*RR1RR7utf-856cc8b055070ea8ea4edacd3c4a50424b94ab2bc569aa9f1fb606a323ca9d8b1?7zXZ !#,r] b2u Q{LXpfr˯1EAj,ݔ3Xةgm{hY g{j'ZKQT]:9H̊龜-eҶY 2(5OL]n2!arWC  )bNwk8E%w!ܾlk8QN8a Bo~a}M"=aMkpeU7+ Xڀ9WcɲKQ8{I;xhvG[гNΐ]}zirV+&''`pUjtv?g5GVH`.-~ƑУ5i=ӪYE5v4[&& =Fڀ~! ~< 8J}旀hj\]|K=,o>{c96u`P?o@6äts^ X3+׈wu7 .j4~϶JzwBtozͩE#~U ĜʟTD|d1Dɏso7A/?7s ԹxovxKE !%27﬿B,m tY|pگr5սmukP2#A0\0p ßr2~͜XfETj0@ZA7Gk%};EKa\AspG/Q4\ ޠDdGowX<-c̷z CsN-t:һpmzn~ò 4'=krzXLԴr\[G&:_Рk:ЮwymFM["?zs590Xށkqnt&z4BxH{ukmU*E +u*je~j[<'%wl%ʭH!m`e=w ;MFu}. G`'RhO!gRݠ=(_m WU j?s# xt6SI`>X.*R"șr* ]>q$``^ rJ6);UVn/ dosR.->6>'>CvTvPu5%.G*@K?y ꈱE(N8*i]SRLӪ1Il bU*q6=g `=< ?J}Y/USk٤91ʘbW!lbztPT߷?UܧlUly扃3\ȅ H:D=H;osQa/p6RÕ vdeةPq=^.]ˋӿ t az`2S|md//3YB&RxE¦\Zu&Bcfjaē)MM6W*Ver|jlSzmڢ՟B9{2X/¤ͼR &Qox)\X( کN7m/꼫o"U/qc-#1[v`SORbmFFJʫ-fLezupu(v3w+ȏ0JdO4?U %}EB~1@Y3K']b"}y!X\6W_A4Y?7h€`ȩ!@0Qơ: q%zYOMkwوɖ)Y}[lG7H`XcϬ$3e/ }q?ҊNDŽrlY "dkGhŭ#sgl~TUMl&_׵I*IJYzZ /nq;1Y a:9}$|3%f S2pWt@ ^EXqQ{L?p*0#zP̃Hkx a#Vb@C))׵h楟1B r"&uDBFjTS.LDc:o)DY+8u(*~Qt}/%i #&)D0aLo$(gd _WFu$aT K@mݧV{ ]#JYK!? xgqnzr>(*{Y*xeXS9YܿIl/䑧q-M_QKICNq+ﶽ FM 5VKТ,;m(Z^фy<½澏ߦp(ۦ;krJݮ-k/r5o=i# cV91  P n&#hw!Fi `TeѴ.}H2X0\2w P C퟈A2җ9Lu[Y%jY`#1q!͠d(rT*Lytj !4M3ֱXx iJKcw $sa-x!~) aj~xt>An=%PgrZ |upO#?~ٺY3"3%:#\Jgvzx9]yj 1sK GQYII3hH?X r?ax3| g\qӗʡ4d)(F6~Ns QE)I\1;|dJrb R>Rw)@}?E08qH&QẕDB4FTXrʡ!_­ }%<歍{'#-1WGmz+L-&~|#B)d ||\֤ $nxĔ6Bklf:#Lr=egqsL5j[d[3jHCdI_ Gc+BT5/)Bj( %' R]^Bُ(8}b-L qm*wCqeNhRf&}r}aWG_4')0iI>lqwy g4ɈRcRLȽm;|҈jѹ'@_ 8aOքf1;馼\6 ``Va dvepT..c 8˺UwXS,J>Pg5fT c>ɔD,!Pq_7odeD` u/|Y $>r |T-,_ e>mp0G=<%+ErcX,).aYOo,pكT_a~…YlJn)*t! ߳.v8 k?>Ziu H6eF Cu(.SLQ O7pG?%vI2_bކS9=!Hܹ;;EN_>9&1A: xjM}8p{|:P"wbQxײt=PcۊZ.LwKx֎ATajLϬ \K!ַ*#, *_{Ao53t4I.L{NӥCr\*H w#Csgkwo]Qe&!IC2trXqEAӤu9bq V @0Lي9t&n2lWiy7,::mHYV`6G40<7/u;eEBu>CNLz2fH|`\UPgP.vy<+8e*M%?ecvk?naJP xd#MVajOM\V3:&fn PAPsYep R uh{yco9XPm8&W:~W!AbF 8Sɴ,Hj83X$\`v2_Mп ]9jϲƜkC\b6w A/^_=(.!IގE 9HkxFnxqȔ]iB'^K6- ^ÃՕ%m=L S$H-7J~=~Y6m+$+-5k!MzDF4)n(ڱF]a0IM3\0sU!I.¼ڔČTYq1VO"zr*MӛEݰYeBq&Ȇ9SY]?MlҺ:YZJ̬ [dR ܍޹{-}Npuw` :<mv$|?ۤUoJHWL0YkcL*,rp1Ļc%yϋp%_9IՖ˺L1͈%A17b:ߗ.%Q9*flE2vW5́ 6#GřG=I>ePcNV(BgwAx(Ccw #sz YD{>}8:~h_e!5ӎ$#^ap-'2 إھn3L00Sh4,p8#ؖT$#jaw!: *R1:_s GU.vИ0'Vľ? ;?(Ǫ>짩@J_aV%~YZ?IR avJewR+E_(qf^Ynh1̡nylu2#yA=gǝR{5H8Civjwլ<ʘߧCa6XJ;ryhg8ռ{ǔnONŭ~<&\q(D*t$8?T`Èw>.$P*Uca8^hj /7) a2u(k5 wot!-YĂx TN;PF4ww6m,/E>bO)щxP,dSݎXH*ř.7 ^3:ab;*s|:gTGc<1zk./ ?ゆ[{+iY9扑!&qq*9x-Nd+J8=D]-Nq)xM2N$8MTM\})ʴ(K㐮:~ kh*ǫ,ïcz6F?dU5c dȎve=Hk(oC3<:86 5M3ssE|(C@0=_ܰ9{se<-b A–k+?cvy"`\<ڌ8 ՗&ɯYBD?/٨9zMgi]w㿭i eLE\ܩpqHuzFJ3D+7(PVɐ6zZm4 dpvPY8@=Nr)?O*{VlufON,HZ>"rOܷqȦǦ_]9;4XVHhx epC 3tp *>Ҙu μ/̯FMGxAq37qjX vPZVoz|?@5hцBlQz,M6_ ]S+խˆ "ms tK*ҙ~xMm2ԕ|24aey'٢E?VhcΥ'X/ī( íURa-Iwg5Ì@:nFYaA[^'2t|(N"#w޴7dl$WUQ=}H>RrL['JxAZ¾ޘdOaHA)s# -NIMƧZfC9ÜJp^1+CŨ1 Kcύ<#kJfe34 g(.GZKobn%[近Z5GhBy7w =_XSL%^zIK Nɶ&r<O1h{H)cpݵq!tg"[H/yucVC6Csy (^M7Y4psyVUK\g9:!/Jcy.Mzm9"0AqD#BiPkNJ%%!|?gnЈ5Q:Y[ֆ5V{iaK;_V1v8M&m:T +`2NI\xQ/66E@/6ߘv I6SǴtґ'D[ q *B+Әe52g. 7y>ĦϭZC;5PbS p'/C'*۸ S,Y*1FF>LyIHqJ㥷pXh)uA\"+SRIk!({Hdhx-/X& h lltC%^~ yixYH -rnŽp#/[WE*k}48ws\pѯ 0-wv YnRIOO)Jҫ7Ș=cD&6$[ԥ@i?Re6DaJഃ;[>7plq bYE0DUwE4(#GPwZKZ%Ftbjw+%[+Jtℭ7]<|쵡VSb)cgbG(nډ 90qry>ɿ"CG=Q6w\"V678 @,r7U.nbJobݦƭBo%ywo cYi]p\ʀ(s^UcäuR}6ϴC_E ;qѳaUy}4;M QtԫT s TuuOWJ!HhĠ_Y^J) X L|, /qO^֓ApRxhFR3zBdN՘tL12i)!BQ?H6?>> mCt20:9u]oӭT9җ;5GCo_xm~[~j ~B qIc`=fu:r|AG[GzlHyi_e$|dÞ>HA85P @⟃Ewh=_D{ۚ*эM[ &K6wH |ڨj%0ţ/K_NzrKp;" 1&8\fƕFM-LNy *W!{Fwj[RIPCfWy]!_Vê*A~'V2JoHYBC"-PK7>hQ6`a曔*mvǝ]$h#}bgÊd/ae諏 3po5%߈ aMx=] ,Ωh!ȴYyF䠚&*eaRP(Ե{*$Nr~K.xX=u+MNɛ070q>68=ޚ=F܉p}yJ@p|ɒKc?Rhw`32)\vDW%$[jbofi.8/'u$ƬMHܠabu(yŞ+?F{aM0v #!o"S$x?K<6)8]8Kjfhah+R*0{~44~ۇoQ6Tm B℁l YvIza_n,$d|۽@@PCqOn?H,tݨsǀ9l~/ʠ@cXւB6u>dfda{{]4@$E(Vbnk&#kO#@O=dϬY3VaԔ2Nn[HrEV ~e@lc>A.&)_/ L\G?P4 {u*px"x!{5 RhkŸԣ?*iϟ;9GagXkLItg \ Jk:BB\`^aJ*ؓCR2#7yʡnD mp@{OkĩjyT4r_C#d, Ab5\b}WWEI0m5ay-EBB5DH|(BFћr2LbZ9VGhHjsGQ#M=T؝o3o4:t-,W97??7Jk$N~8>Fv[/5݇|9ǻ%oiV]L#64V#:;*CC[J\Ѣ& ˄tY 4slUʔ828] -L+6OiH2S襏N WmXWVGiO l^5kC1›>!DnX^UCj UuHrQ۫B6^<~eJ^Ic;~Qe UJg:j9$aJɦǭ "N ;ɼS&yrU94KCmuӺsj3Mb=DxԬ8QM bр^AEDxV`MU_qA* 6lewDCAvuHsfw$:蟳v\9;Q)qvtc-FD98 VB_ n=y{f xz|-#|4=y@g8MdψbA /4MEt^$ErlT1'C7`j@-3HpM;]"DjSy!ˏ~j-}\uqk܉O|I_RWwQRF)𖵂7`+U:&+ GN ̳WT°ڻM-(]'# EܐH,!(&Yd$ozvꆍG,#E|Uܧ "6_cTG*'~<᧔nʗ ݺv$k=],.&=P6`TaEbhq0z kHo.dgLݠΖ[ƚum?7V;B ^mY2zoZvH!uz@,_y3u-V>.䳔X2v8iD[`ߵWJ!\ܗ/sN6JD+~Qϣ̡1n_|͏}Z&ƅ{었gUn0{zx} "l'yH{Z71.J8{"bJ{ oP?m{e}|^yIHLP fh챓|t(,u1U]Nmt @ͦ͌jԞdmKyx;wDgvTGA4KTjmbփOXPO(op o3&ri;Z6=(a7줩Qv0~Kud/yRl!' ,P2Riv9m/I4h?P)I&)ћqMUyn/Ʈ/WCD% ߅k~^(<.lpxߘᗩZj7ɾU3NL@rWFkowt&: -t|Ώv譾[^e4*XB'ōЉwPݛ|ynS1mMSk;c,'QYFKr>-ï+~M h1A 9qR# BUWfV}ٱA= )!xI\`QWzx>\ؽ)n=Vw21u!W߸ΖxM0 ˙#R cI1 ۥyvY[/j fKU&qd}IoiVh/fZ+F =W:42'-]M n|/kG+ B= *j,Z"kE yZv_|# =Gc( #}yc=Aד@yƺeٲ*P w'$ ϼd9 vlՄ +p:"8 7DB40` U& t^d&ږc_ύPfڏ" Hgrz h@+N ]hNXӧflNܣi|n'jݝ:Rď O\KIF@oy0qԡ4GJG0t[ Q>ykm!PFљIbp۱稪Ꮫ4ܣyl}?/5S fIn2-x YFr1s ++K⚉7̀D_ 5o2Ao2סlQwXM2a+n0jq%cDgK̡ܺg\a ~]rK 4k-x>Jrp^FzY xe$DŽz?`x%9zo3fSl`P3CqQIiv7-WD˫,Gfrĉ6o.Q_ujir7:)l3!8c0O=1}L^[ mTt%U/,/KDpȉo׬-j7ܗ&WkVTDEE9KZvC9W&$l嵳MJ饄QxK_SCہ.[8&geEi /]{≰Mloo0RbxC>T; .2Eh|r- dw Ήb Z8z.%|57=8{6MycӯSt#aCBÜ/.+Xs|#)e * ^Nڑ[$|:[ϩpK4Yl|i%_̝xj[r\nB 8}NBl#>O Q/1ұEjhŻʅ w97C>2"Y1=PRZ>*q (̭6;f/B@h #p5m/<6 Ox4ݝJz7M/0dڧYq]_KH*AHu<ΙO˸D@D~t֫^OmIF3=:)_IBs<=("pKw΄%WW޾SZ&7~C"m]YR8To)6*Jy{!;4 rS;}TZo3RN, 3 Q s5My䆑bY|Hة.7&Bu> a%p,wî3XDj:NŸ@a|Z?K.sca|V"Z pDE v^r\jKe(9ΐ,MT-R)&GjTzDc9`Wrpx #0g;]\4ml=VND<.%hi,&PLU#[yŃ|Nz-MHB}B > )O$a]ڡs3]:'j' }FۭqKA4zocu2vqO$bK;`B+1!"+Q\c[454qUtFWrĖ] ٔKh)s94([ns7=3xk]h A믬4V$)CUgr|!v~tʕѓIZ`]!hϑ"&>L`$6:YBNN]d4lzuٛT=FE&({hAM=2"S}б\tQq-,S0k2Z 0`j)X)eɖI|D/%&QG?C?ێ]A!x?\VzWa+N;֜QK!1h]IJ{/M1(Zd!A7hAMAxa=TmZ똹azsْIHQsд:[dhMB߶%3}&io9;irfmLdL®P)ڀƉ97$([ܡi^Ļ㌕ @\h< v\oZupk^a5â*M t97n,!1(qjflU$իq^Z܇+A?y<7EKs/;m?xY߯YKӉ椹Iz2I[^Z ^nͼl>JL^kt^TP%) Q'\H~1 S!^Y;d*p C>ZTIHy)ؘ#g>I)GlD>\]oOdᓁLޡk iZu̜Qit@/+q^2Dy6f9i2lRdH^ZLE 4 $;L6AzDi1YumcD {o@;Qv!ᤗ+U^ERͬYӨ{46ܰQq5ѩvnܐ=Z*c#?loyаVpOXِqե8C*>ScZ#(oդN>KQY,2 ,Pj>ְ;u0+KM!(Ifpc e"CdIg$&\@OlhYUK]t(|JqY=gT ^ӧX1`2__ۥXyYZ!WD^}d8a'9="UsQuKqit%CPf=F0BɎ{'`1|DA׶D3I+Ba_Oy)<W[.-ױR6\G;;dzW e4(/WH=%-@ځcShߜSt*<ͺ18dԣsA(xfb,c3,/$YH%pēn8^0FMby3z7?3J(Z*9SyLm$tf⯰kx¨'Vi{5gpࠄ tk?zd~(0]C2ucGGr_*؇?[( 8gIL[j`"gDsP첶i& l-Jnsv+?y>3PR\\-sj.(|fYЌ_G%`ɳb{hÌ<漧Rrmpź|NB)~ ? +YZ6-,Q2:NXSN)jAVR#y΀҈M:`,0 (<֐>NB }S12@dP~8 D]I5H|[| EEΌS A^7s9`Yb{ߠGK!!AE+yz"Da_!g=v9Pnw`f"Akm"G=iKuRB4lJΥ I{ Kٜ`A(:Hj 'q@צnM v_g.{VR3,eb/gkR;uVjx~ jfvGXpyT9uOV7~|PM/7(>}c\-0"Kz8H#(klyZ4X+vRwssbNn30/PاIy@1eJް@;CI 7\/Ě 쐕j|̿_{GTnvtTϑ KI6ѻ~wzQih4fcKW:*ɏ j֯ y~Ssr J 5&hzl26">)ҝuVApDx|hbg U~^ڳIA^{:,EM|xbCʦE z#M!oSˋN*Z8`l35mΏ:CjJG/&eȦUY>W DW,{N *?J6ua[-:@[!O )dB&g5P{tJC$v}hD<SGތp>ӆ߉#GkRvKd ĆtU&V[r Zf12Ф ;ba9t|Ҳ"C˙}YEE{ˆ̌A5S+B۽w>?h剐g0p d' a5/gfxFX#UB1+́XVgG :ԋ|`H\}ad fa|i-D:LLeJNcy2o{х*.Z:^fӇtcWƋ8Dh̛_j ,4,n$P&=k@ T.MB9Ζ6-]_~-sOkO#Pw=o&~h )v E+^_ӉrHF)ڥl/-}Rz3ɫ}tyFDvH/2v;Eːv7}FI(,!gD3"[ A@ iz\,Ĉ>4smvZ -Qz.%ۘVHEl4q9tJW[e TmY5s >#Q*h͉vX 8Z$ZǢ$D eCzp*/X2O8gƧPĪA؏?IȍI~)ّ`1'طI-3KLlE[̺@En5zGqD 4Ԓ!1%"GB 5A, c|vAi83d A W$&";1O-Sx^;eAdR } s֙Jss1I1˾ m( Uci|CTrz- vNR\ٷP#ʼd0``s wE-hl=RidEn^$p*Cx-6h+Wc᝿{C܊9Y͛՟ȋcMl1O"VmOx -J8Zw]XWgxgc?PƉIĹڪe!X l.wN` txyt1\EB~# gOڔ*xKۂS辏&G& JZ1-lr[S;QzPy'w*ut4O̩۵!'H[(zQ玏 c0=%)ۉ(W5NIêҮU"ٍ]&$ /c}Mi2(f3?ÁZP&Ċk㥚XcX{L &$ z3zK AY EZupmO߻|uh/DN~Qo.9Z2mnȰX6)ǭS){d۟h;mw3`hr۬e@#0~'eع,iJWͺ ^-E(4+;aP"AɳHvx5gΩ}A5NԸWؽ\OD4+~;E JWb}#/aKC@`Օ:؆vǏ04\mK~-+{̊CyNQ?q: >(Z*v q OMzxٽڮC86G"SxA01f3ܰ\' IA4BF<appb t} e#jy1ochVfӰ Sm(9nݜsX63H@r?l`RYN 't*$!!NǜPSQ (eh $CL 1P`DZO "^y&IC̾^Y~L~ x|ӥa%c6VQ)ű1BP#s# q Z 84Zn<,P,H8IuɔιCU” xBraq;ScoS潞`+,>;5zpJb"m`#$x.tn}GeH{Eqm"D߈WаS5ɺ[k{ݡ-pyWZF6=Ջ+Jw ?z3DA"aV &BJ=Nw*.E g,Rg djT#Sp %<= **hv=\$bI I#v _ ]i+eL{qq5C*h({ϛ'7/?PsLEu7J̏"J2c 7x9dz5Č ^;Ω/=)޸Ňje塱^Vt!œO$7T0R'i⺼8HO_4 "ĸ= yB4W=]`|g7&Ҝ.vݮJt@u ݮL0) uB;V9נ" ~_&q=5um'S4Q4i_WZ̎d<4kxJ\:",[\.1/Ī䋽4:qsFg/\Ũe$w2I =,2|RTLWDTO%6ZU h&0ԏpT:&@vФAS}-V@M0ko`0 Pu p &q3mv@; SGidsH5~ǚe;DÐ3\Ax_P'NRm܅cMv 8`Xkz`x5`kލe WT9Ӌ8kNf3638.QI*ֶA!ʻJ* q%I;"4J]]8Br&"VW "Nq6bp`Esc1xF=R)O+֚umxxGƳjA8pva$ksvD[ZKٕp?Hhe BTJ,}WZ:man+#B!8~d3Iesz7x VVYv5 9ۤXI~,;tGcU,C L֩KTO,/G0Z5ٶMSx"ǝlAoBI9CL 8H>F+q۹N_=<Ǥ:LZyY)r܁}l{8&jf7-~g>&UQS#)lnZN5XۡI)JR RHf+{DwSYxtIy6]iw$8}{qtTx'uլ*PNxG(;hAkۘ^؋5Ŧ+=}[4)i}yy3Q-^:}:8TbSzU%#J(::YOV1ڦquU?4ITJ6ֶ8|UP"(W?#75sp.%a؊Wqt]$F ۓu䯫<&f"igmR0>.ս2)ɳ~ߪVXtD2b?ʵ?.+=XY7JW_R_[6Mav1ĎY kfo/H;+x?00v:j$C K(iiؼYlhaԯ*10v-Jި?MKnI^=myo7\*uN<3[C 5YdYnVvsT o {U cj,{/$!b N'77ϒ6Ӏ"FP|+ }rT;~Q \sHvdMsYQk|l55/TU"F_e)t w_@) W>/\U8E$xxi $b[&{ L3(|E[C4lW"hυn>C;0gBRzY;&'٧]] J P,Z.2p?4@="^i"/]nþ$WG~D7ٮh02ӉKkwbda\]EK+ 1~RKlQ*YSa[}gZ,ZE6cIQdӣoڲIDx4i{350²05'g#!Y_ F dJ'[_zJ␆ P4׵E72SƿVl|fr FIKtD'Ao}!N2 uR~We/;O Nt Fs) 訟,9/,,uCqY j`[OIԉ}o&=+V+ kOw$e#1c~^I}Ԋ>]82\ @$f}jy(蕫W+Gց2? Im}krGy"-OL*Z0aF `r&nZ˶3%pz wRa&BiFLXPW:ȡ_EO5Xt O9WVtWmFC]X@ƙnՄ mewŰdu'_Ix #W.BA=($S(3hM,*f JdN: 8Ǥeec 6K#6>>Y/S})HJv |fds)q!洲eo(&˭t1~@#W-"z'tw1Μ^Ʀ*:5.gǪi_|ٺop 6v`">ʹw!] ,o` $"7nc1 3N~G='k`msMzLl9<(-WX9$"oaOzoWN79Y%zNU_M@pMھqRWQ]lokqVUr)\A&%)لos/g[:o eoH OrՖo:oN|Z;i59q'2XQڛ:k &4.v0l6bK)HDGQ ˋ\dywyC6ڤl!\S(SQ-k(ٻsC5W#ׇ^d@3 '|\mn莴`H)8ͲBuNz4XqX )&BzIY FkK%N!M@m!FU9>]× -ʄs;5{KhlZ;y}ܐ#;$u"gj$5`ȴ-r Å yΓM*aQ_]@+&xS23Yׄp[|wڅVj㹔zRV8}u9~( o;&Q)w9;qS1:DyU%h)܀v7=Kd`Cßp$Ǡ<?N_̿ 1^m>~>ՌPOkl,oA-@f z1|gv/e^}oDejQU^ꢵzՍVBcm+~&y<^8Q>&쉾dRtM.tD2\Q+wlB*cNѣyO, ly7fp^))`6#RݴP:ًwI+E OE)zbX6~AM4Abр^1Xʂ{ƍOI^DA>kDTX B`ҬaKKDŜݥS[I] I+ 0TB9 rF,C 8BmT‘o7l oah?4 O Ktu_X(B_ ۣ(- %EHC<UG#n\qBÐ@(0r*oIj5[ b=pKEauV fZ(X`hU^4X7jR:4kItﮉwc͌@~;)y~!J_nD,uVLAm<#eʜ1oD ONǢ#oo evVI1¬@FgԈliok|]ykA?ұp#C8U&pi4P$/IԒ j<[B:aUmfh^Ul1( A.ε<.9V FC.e |#"دP 'ZY2%]s@fO!LMRJF3Ze)#amjI$W[)C *Ic#c~\8ArGMnWd`FyyX2[̈́]''|.Y a@v-+N|S+ |mtlb'|Ck1M96#2`,g 9krO#cۢYA#oʔ^%|?'~9BYwQ|} Opn>}JhnjvIp^6"oKEtyeD)Z7'!A$'ӡ;E;php̱xQGC W?a$\=Ve*Dh9MGA rO]86z ^mbwE> yR[#s7"2-1"HWfW 6Q[E;ͩXɎ-Lj"s-cSpwW(dDp#z3CȄx  6]Bm> ΓDz${<3oAX:Wؔ%Rk_Mz' 9kzh] Қ#e'VR/]JD ,Xs 5JMY?[*PhNQ_vT)Sh>jUB#3.]#b9jCO`gMWA240aWXa{I'e!Ԕ. DbTMq!'_5yźHY:|[`PK 3n"AC왦p,l2zji#@e[ } <lagm.|ѥEշX 1@V.JXU グ%4It-J?Qr\R '~s ݖ;zdu_L0L-{%m c'p̧1Uj¹Gi&#Y<u+hHX9!z:gZz E!zl%Þ!90Y+w6[Wʾ&LeF.Q$xdsƗCz1絼حdfQ|@8ax Lyuk0 ݧxw+̸QuLb~y?sw\WTzF/{8K‚#ڈě!;G"3;o!d ?C|M]9+n@ v}F}<[5\C+  ο\yP,0cץ9`A~hʑ.Dϫ𫄯=b٧p*tģZ'&؀d"y%(w Tc%kM>`sM{ .g{ ;!n;_`ikmXx3?iw0Jy5Dp[-g598r ̨8ʂ.nʖ\J/+rYP#.467B;`a=|4VD9lT{#JTp=uΙ'8m^iG(uV FD~ðJ8oTe5gN {"Ih4=܋REpy7Pt0gG9{l#j3I=J\!էTd<+',Ir 6WQ0B[b@ ~ l9^O9md3ekfٛmGFW @6nX%CD)3SSv*bЍ!bL_[@x 2vk?K7[xKV@ɭ<"I;f.-|ձ,tf`W(N׬ lV~{TUmS8J="mdn .}dO~"f%643JFLǹSFѐw*$ޢ'2.R|KÞ؄B4 J6#& !mRuZg y܎@K@d[ ґ}361pKR;H6BݳĄyӮLܺg(Jtv2 i¡e;DR>vJܱEOR[C+A&''lT`/=1y+Yf76mcw}>"z]ÙʂPmi([E3sg82:P^P:c99Ό./Ikj^\19;V%ao[oy<-h9ImPǨbcl4!̢gG Cảq$i@.hj!JETM[rKqBV@Or=΋un5yYp!xbuF|e_Ks߆3Qe,J̞-tv⒓L#hԡ^n3 Q oS#} {@uT .޻9Πvٚr`$NZ+)N+iemEwL>ԅvP8&*MTE6| WX|rm7qCG@nN>F ܨQEӂL쥯9nP*Dj*G[}wv8U1'7yCI@_Ed~'L/bСq|% L@'wچ6uqjdq/ch+ҥ5]w!PGWU)p)j/vҳG ]rV#{aԹˎ/鄺?X|N Q :'NYj81w\Փ N|i\KqeiZؖq0 OEoCg:!5(WBj`f]ͬGAΞ;?1Z2WOԢ\rp[ ](͋Pݱ0uqzPnxANoY-{E[G {'R,ܾBK#h10(9<9b eҁuY̪Y#G*gP.]r2#vr^D'VǔIJf2|wh?j"I.zxmUV_+:9 q_Oy cV栣6b D댍$k4O̎L;10 =t s|'I6¸. ^\mwNV~-X(~.%fHK|;M3L o0} _Gν5i ޜy*7C\GU6%ˠ"ߴw>/)yW,@)0i"  KhxƇ=O;67O{xk! q ȷ8mGkj%PS}ھ§_އSb:1Uf7K}kb)Rrlt sHx!%:_Fz4;y0\Mh+yltJ阮D&F(fE:|wT2021hAn8KqoHha|UmC#ϜW]L(]`HCy&]zˆWuQ =ur2a*Y!tVHaV]hySDrUku@T. YaOgNhp4-jn?)azطoML,J/}Jɋ c#u+3 oF*> ūrB¯\1 hEߎ*hJ+c4RU S |0 Z[Hȸ|n*_tuQ@7O5uiѵDMU"xFbܓJk%>,p@t(>oX@e=+Γe&߂yNjJLPFvt"3,d1S / Mr"gKp[l%ÜXaUq_Hv*!&T(UqW @EgT<''z* |sN](ĢmB W[',737Mi8Eiŗ.܎}\`D?߈`l ?P|jnk'UtUNehV6@(0\B*0[=rٱ!%:L^йk_ۙvM2܊jؠWp?yrȲ3]1H2>Lc[rXOX%:y[-WQsxa`䳙mCQ)lZ~ECz0XBK]"%WKے?d#Lm V/JU,TycGi$v*o$6(pns^.kSxB}Qiā[hf67sE7~]b8a"(/`N_z;TpLuV\4X=_@꒥Wv7FiK#q7C$2eS7ӕgpJCf_rǿqtLҿǣk;cG*+4H3ޫR83CMVRP<}o OE>HPlk DubQI\ j -m${˅0E*ބxؕJ =: [7ԓG)uHT!CfZa᪡0)oHfHnְA|;X"Oj& l*ڴ]y m'2vUoǩVV큁7حf9l˱IpQ`2%idz x oqChS8,؝iW|p딣 -gȹ*?&fjl1vKGQ|jc?&Lh=7rshiVtnNǔ-O$H*]vQdx>qc"EE3tIC?ߺz1'+Ȓ?~DPjP"}-seѐQ(&Z"gݿ/X¯vᲡ"gJ (I13̩2XbX6hൾ9uWX<U Z4.z+(71S/ ݤg3/l|k6& oP72uIo)@K&fϫa!Wf>l}LpfdF#.S!-P:ݻIz f&CI2P7roR%E^pzX$my~'c f3IzxT^hAy(ZB5m#UK.6vC>d@f#+jj!* D-j|)dnEFo7-2~zo.l`R_ sVv^tDΊTJT}Gu03lf{iWϰͬZf {v.V}UY/A}z[| *irj?]ђ r{Urp G5n&^R!K}4N6 <H%"x pOPXe>JTYvpfc _BFٔw4_xBf/bAX26ϊVED~-UWWY.Su4tNQ%}qN,H}ЦbAxhVOX&;HeyJXRRٵBQ0jdڨx-t@n7=,8pVoʈw]kt(eHĸ>;`YL;%($$`ו_+MI;5z?WX>dU->P!N]x2 /L[uDZ*[L蒉1V807xY@wlazU6$:I~W]R18Ϸ.xk0|p t7o4ý&`XHU4 >mp&B7hC% *t3HE.SŐWT!OBQ*VR$2CW gv5t/=qֳ݌,ߛY78k{5]}]sMtDžf"dFG[qrIhW"`M}OHg]:]yD1c(Nѐy 3Mѫ>1Ӷ)6a"l͉v+t@~]KYJN$BdhK=ͯ5]pulAϙ@pܠ`. q|@4!6QU:kͰI#]]R4%sIfaqW YV2cKeVhP]m+3 ZGos־b$s)? @lƕObt.ۋ0.{X,t$/x]rdO$o3gGwҦRLgӧ\% X&(9wz.D m?\oqQKL-! -!C/isZEN2" !tdC _w>չ [ i!>}݆v֋fM/4p,? Pkq2[/M*@F;)Mӟ4Zo{(\Cٹ7 #x4jxr<"冣ǬRb䧄S8ÛZk"ܽ7~V=!hw"PhPXG2kJrev'"ssOزF?Sb#`|ˬeF'H%mX}&tJfeHZGej_1ypl2?(`#Rz,6$xѼåRe/WtЬqi]KuM$Vף%DяVQ4UxgTEMg$UW? YTPI1ȇi,4N"6Q]?,m X{thDL>a~ƾE,Trz./{&%? HekF='AHM!WJd%o׍+L֎#h#[[uIl&#h. l7ȯ{ɋ+8Ƀ-}Q8+ Rx8֟žyJf\Έۏsd:'FYEyZ&?oO8Uo2K#;#(:fS|^gO4=b78a.qg9$Vp_.S'Yk6oLM_^fW8`Jz$?cޥǞ>Xd("35*lՑRg/>wG֊"*J5 xʝw#WEq%l-E Ib&o.ww{b)hu]@i9i;`7nQ fE"o%=u6ճ!=-R@ T);(>4|}go1q JD'#4L(Y ywANf؛sU1;qJ ư!F ĴG.Fn̕C&Y T۽F<&)qP;UNeT3ɢYA[I. -՛YVAUzKR[BrR]ϕHe oݾq}l,U=pFجaS]b_lQ> ۠lRkXekoLr޷k[.~wEPKLtxRdeG8Gq]{ӗ_sLZ/)ؕ<,8ڣ_qEpb_pc<3.,-dE3BxB U7F? 4=S3ɨCu/Е6/Ce K0|/r^ )p%s#H<4*f88! fِm?‹)C|z5Lbʩa!TyEx#+ tmQۋGӉ/!݃u-\,ChPBqяD!HJđ; rk2DYSQ IѭwS8H.K?eX֨ _'e|>8^X̎DUZ2_2c 1hW93ټ%0.ӓRtfzƬrHɇT];eSGd?O{h$ժ$ o3'F(,[BG xֈK@J_T _bv'|A-Ί躚#g"]<SO%x>2&@~\ "rqq~MEK#=hZ#|tzv=./_wQ_(~ y =˜ C,Ro#t ԼIouZ}F&ݲψ0D~jlȪv¨|0NuG|0aº_C#ބt:"C5?~[3GjSMeJ1q#Aj0+0p7a0@thZ]c7hζ15OfBHW 0ZLTZqBȖ2)"tHs0uK&x@ќj'~%eqcnVź7VbmڞN!ڑA!Y9t~#% <ےftސ<#j1,$C,B<;iË. *0rs*F` H/ChQMSb) aȅJ@n4rE5A'L ' 7armJU"΃9h5c0OnzǴ01wccLP!6zrSt*M}04Cx]p!BQܡ&~ڜg[Ä"yHVl5?rE(K<ޤԤR}{L.cF7:GlB<܏< z߲_`.Կ\iGt `9!x͝ݸ1Us""PWݡ}Ǹ)DC%Qܗ/QRj3z ~&mJgT1Rd0UAgrFĶ*n#w# 痼 :j4a9YRTѢ)/%WoܾV:MI#agu:~ⷜ䠵=.7p+`TlDߒ'`m;myd!ܠ<V]m= 42)ٸQmC)Ls؆JXͭx"q/w)?dCv>)d+Q`'k)Aڶѿ4 ;9Ҿۊ笐H0w5au W=KmPQC"߲ N؂2#O:B`dA:aqUė,:Yrzw]6fX^Ȍ~izxfNc" =5s&@J#V%΍ƾ1ǹ IAZkB_6Or4~n0B K(k_\}=T+j*Pi#a![!0N/ya2)h\ /|;5,[  T% pbQ'MHUDQv[۲LBXQE]-IYT  ?H-@p&fLNU PXbBfG@}+&F_1*,E9*!@+75Y:a+3P?ih?KfLlSW~7GȘYxoB )n'e[Mgǂ^5!gзj\t.Jb@>FzLJC jZl1ltxShv9D,Gˎq:r9384}܇܎C,p'plþΐ=A6/L_ ON7d:4fRu)6a35oۑM,KQo HPCGpBVȦhZr!gf{s_ J.b%;s?_܊l ÁNf3LHv22;]@ĪШl>pE)f6TQ<ƒqWZ&8@#grM!2K?ej oLL{ʢAIpb#RPr4,mڃ'G(.]L,R^GHۈx>Y=<;J I yAeϺ^H]p-|J/U~$]J'I͔lwv{d!=@y@Ō+ޕ QsQgߩlA4}NAj=OMyÑR+có/B}l,`+ca)aF(us)OTI1Ӳ z=#HCBydpTj1^ !f8g_gSRhn>Ģ .>EIdg?PWӇ 886lyn9A#& d 81ֵly-q eQ9+vb) PBb\w]W)yɛ̿`޽r[V{ id4'ɷ\1 ꤰӳr2 W{ृ]h2nus`&ppl5'qxK_;v>V&֎]|ٍd ? 1C;kދN.%Mf+2n36^ߊ{uuCEVl4v )74ӦpG \M+[6Vֿ̥Ԟ$79ݠ`u ݙ:#^A[QVNrT/6/-C*gyg|ugJJΧH5q:`~aI*{SvOWzٌD* 3z{OOD푆l!l" WhDH]%k]h!#`mgȬFjm^+Yrqcm$,QwɂHCL5Ik^tjkƞo}b<!ƿ_hz;F _WRFN ,ɺݻ$IimJͪZMF~iXNEw>TWgU(<WEҵ0;U| s鷿;sf x@ r4#"`f8r60A -Kx(65!AG?f-(Q/ÅE)v)b5~U@G3i>B++ڽ" .tuy(aܻ5YiluivQкljEaF2,;^9j1JCKC_CvYl:WqNgjCdʋR wphvsl͈I/82@!_2Br(qs,;fT>;%ll%yyaHbͼ |--Ivg WdueaJ;3Ms Iu*OYr͉pDDX^*7G ƶ+>1L7,>OIT>XEWK W̖L|yS;+K ӄr3^Yya&68GpkTϞ XG\7.U{V=a~ӗƊ7I*[/s<:hˌx&ZՐL'P0bk&:\(R,>?bĈ[IcLQB47i;9sm$mHh<>C{Z$s|u6k4;ϭ딦@F.BnBĢ# !A3s- wf_ ۠/ 11̙ LZNz=3aϖN%+KH5+d5 ~ ($Eao0}8N2FGXP5Q_!b'#K33> JQr I27w%8a [6TG`K*|L,'NB3U#Ę  q, ӺCZ˙.I:ݎKДe#-J`xCtٽmM3LCr)S!t%DXr427<ݗsa/Fɡ*~]k$ZZfIN@*7%iw~fEf!W\:<c EXHkosCG8h4_u"*nVJz[IT-T+ /e.e%:"wBBCЊ>Q6$ *-'KalTjB,U98PZ9amataR[gɆHďF[^` =i0 sK^r>y̯!ba,G苃 ЅBsjp|i 4ā[;A l4(U6r 4dk(OޙAplEw/b'.rr}ű @\ot/K*Dsv vQiY]ұᦵؓ )3=6sTҡ LHA,ӻ}x MMξ}#"_RzY\O`|s z2,͐G<ކ>:ښc MGni#$F}V{Əۗ*mw]HZ?<}PYZG? Qk[$MS} MM\DJ)bN%Ct]@o2ɳ%Bm_ċc(V0[`d8TXmpw_ FËidh=׀(Ϙvx2USZ)Ms҅ƒNSS$^*S%TQEiq@hj.Y>9Uf {F*9F b9p&3-p[(/tpdI| K4bG*uq:r/2Ia`i4z]-n+(y|sik U/h-IqL]UdEH~gϖ܆7lZLk! |~3YCO.P2' |=$$CP2:[<$ډuݔĤ.~2~!œ^Dm *r[![۴/4#trm_gz#5.G3;!fEBU "QA$wEvLas# =D-h%iTw!ʈiPfֲeGB7݇-m?:vE( Y1{9=jf0 ٜ"/ PC1(~bfg&1r6 7C6S_H6({>< 𗿖'BSa}ȏ'ɷ*\{ RYuj§qܼ‹᪟qw/ ԁr4]}ihl; {pS ΝG׭Wbe1Ft6J-`MHH}oەĿJ놇*j\`|rj*u"\D';f|LТ'ıxdݦ?p/wM} LJRn;r.в"ni4tt(;Ħ ,;˩3{y7הG/Fy"% ӝٛPWݵմNNڹHBa t[^wdeSò> B_w~ڶԋ!T!^8 FP~#,>nL-)Xa\5.~E,NȬ*s%WHX,C]l[M=j_s͑Juyc6zF(b$n9Մ~oc=z˗gȌiŗ,X |ŸW{=`]."͘R45=[0! R5xZ>Զ* {3 49xrx=gN+J"{Ɖ%6xWM Ba*l97 oI,,NRhLqQn‚_8wP\aygg,[ݘ^0 tcubzSTz<(s*b5h Gmw%{bg@ SԿbrQ(|6=x( ҍIA HNb(7(Rujfc88ivؙ ;ԒD5*?!F5)t~nwjŔʵLQ?ƨRM(2KF71]HI},*B,65EڡH2|Yǩ?3ӝ`V6]ۋ?MЍ~)a' @"R׺Gz)XUa9ޗ8d]h18gjh%jhz`~!yڜ`8-MfnC ɞ㱾 `JʗKvvf$WZn׵SʏqX=wK9q* `-6S\\<a¹lŝ6|(1ND@W.K~Wؙ37w2o}'it1:K8j[t_b]⢍x+TӤ իE^)UO-f3/nE Y}F#us~ۼS32AuImp7kUj@c눏 *jƓбhI/%;wu;z6)tgbe4O cqM3kq]z;) $Sb-ى( ehXJᶗxb0#[HR^kR$4{pAM/|"+>Z zy㵻Xi왛BNm(1q nQq\gTng;yb$^*]B,]$ Դ}8ۘ.-∛} #䢼=CH"\ZN8S#~@L(Y*僶֚i֓S_,SRdHPK9ExUv q~3@&#[NN7F+(*(`Lv8HW֖5J(4 'itHG <^K/c{^OfjFвS׵heYvbp|4~JC]0F6txh TUAY*(]"@D^9|xq߱ղx#lLu t._p;`ː2f[)=P)n94zJ1KfQ?#[+}00_SS&`_;݆UtBmc#1a6zQU=c8&,ibanZGME*EY-AV96ŬV)&vJn2hd$-W\xAxX~oI+8YX=k+O y8o+~P0ÑeՒD"d6K Wr2TQcQixPXM@\#|CǼҼ :ޢ:Oeh@>_9LWʜeY`t0wqƇ%E%tr'39vJ/. QdN\6(r ZlE5@!=]B8%k)m$/_B.VO<5%w@/:̤<2\b Нȃ#_LhF<%C;P-+:n<IIy,A)ILx);~bF7I [0B]1w7v3P^\$њ0ߓ)lEU Te9gR!93s pQǖ Э1!AuX[8\Y8]}F۱^{ۆϤ,}@6,^PDշ~ ~i.hy< [($V]56|ǽy*q+%: DmS_q;҂DƂGozct)@ޤG8VA Dpvxng}˴cwz}.ξ&VZs]1i (_wוy"#nzW)FZ=s.1g!6O:"YYY6Qƽؔ]=s.sϯ̀6h_B _.@Fy^H/16,To^uA}A3l1VaDlPE$'L'R. gӹ"R 2fgbNf<iF '8+w%@`\ ! |hL{>Ξj%Թg292+ F2T8@maI k=]~<+ꓳab8v2QUr13K}" ˦A`H5s^R5? ǼZl#(R+Ӱ#'%m'ɵnPK6C 3137]``B[*pF휢Ǣ^$M9nE™i١2$>)?6o?Wt5sm; CsM8G21ZejC#xy芶 J+]P' #/*pLaҜF'=r։+iuʷŶ??%), QR$G 9+& ."e^ ݥeX$B91Akp?rIv7~QQk|^VR`b{H2E?Y\AD :ss TT2;tR!̗9@Τ!Deny[@IS+xY[+CSX $E5 'YLxWVC&酷vd(ʌ=qn샢g?/& {I 5@xw!sN3y:] -d-ٝ<ΝO4J+oF:f;"w$KWjGVx[%9^lRAϑmgP/j!E$Ӿrd^",lxdjgPB$Jsmdtڏ-?rqA3ZBrs_@Ԃ1܁ L<U@M"VQd kbP! ydτ%LIyHE&uCӈ7ƕ#>}6.CbU#B`v2#?͇iEup*P!4a5{4y 3ρHը,hsCt2T;l(7}v|_b<:GUK(')v)>zStYK>!22=2a [=vd1-::lFy"0Bc+s%Lo P9~ԱT&|^q69?e&^[]6g6"]j֦HKvLDvBPS@}\sƾrdE cH̑Ճ>ߞGR Ѵ N)"H0C)};vې/H_sťSTH_.K[#'O[o@G.7򆎭EIegj%pMjt J&2mڪS='Fq=`81)6=3'"s^ zT*,5XQ/+ViEUCvB =9TvֹfJ_+a:bE ӳTs_!ި+ K2Oj]{!ώ,-IGBiBh(]t"1sUۤ) D3m5Eeɱ;IQ%LlVAutvW ˗08bwIxu[=^($8sm^ଦ(Y oe.YV]?ў0Kܜ|tf d*BEebl;Dڨ}t_$+ͽZKKgYz%OHbFY5xɢy 34؃7c_5 d'DfŜl>S3S]6.6*O zvV-{uFH -QCqlI^+Ӆ4iĤ$ RxVmuwj񤒬dvBJ#ߺJl5^F̰88(cv2!5%\އMit£(ԶO}́/D΄Zd5ojCȪ-k[(ArO-Y{U K$${8h,B L3ϴ:9H:VnICψ6)d۝ oVEyk8yBeS=T|wH _Sfz΀BPKG)q!q\{֣sSWvih@^#uGrsUJyFV}c6@Z2ZM֒.f? `<)K0 ^ڽ3JZ͊wf__Q3hR+N.|ȕm)Iקr׹oRf eryf<ˡ9oYGg84Dcz27K1^"նĦ8gϱ5k|N hz`%6q8kj I>@DMMZjDːwJ^0 TI2e+̟g.|ĨQκITY qC8R%ELKXzrwX3t#6ȒVr`9vBȒUd(6R Q-ZMn8 `Pg֚lXV2 Ze6ǰ(?4&5(F\y 9ތ cXyrZmio(?q[l_҄+p~r3o>H_fIM\X;܂wC98.r-XZPSnhs̔ $}׽;A:=䘃n?rv}ﵪz Ns[4nO{)9g osJe.g1Q܍{{%+͵IZvܚk0z5lqS z 9Dحto0x?`HMҷ^>. OLՏ0ʽgn6M|ow@U$u B g[3W23]0N}鯅UyN@'䟗iX׊SAn@Ύ]̠G/k)"3"{9X>y2;Tuxna(},e~.GI,Ȗ-Q܂6Yy(_HƤ!Biݖ$vcQSfJ=21 ;-ȷnb'*IC.?qJ{.=~P&Zˆa% j#BjqFJ!\VvǪ*p#vL"sφBS0!`_jC;%x>1r`_J6_ ij`"`|+=QH.Ÿe7 g¦6 ~,dg _!9_]j2u9Kc8wu"̒ru^Ha1-. :_t?ymvaJߍ U<ғGeUwi*h!oŷeԮ(!w7]Q >Dv|}:(59#+;ҪFIFGoqq_'uuhF`ͧYjdƦۃ,dda6F/K=p2sK~1ҍ;IkZ XpA4OM[GdmDq}s.t RE^qd"v-:ȢT ീ7K72 Lt$={eM1 w祶GxOWhz[Zi '%jϥl.O?sPU\#yF[lN:{,qADxԃ%<$i )[YH3F}ɪݍ|gay'sBgBQ@F^Ѝ!Cq>jinL=nH_aQOФߘȨRgq8B\H@(LɹA~AS,\C9.HFpªΈ~KEz0$i^4 FB ӅH3 j2˧KC'EBE@;G\ FC#=B SKjD-d 0׃дwVB*90_*bT#@ZQ(úsHP+ B)|֙+]ؒ=A.)Ruԅ%h@uLRO-.Ògzr˼}:D:YJ VML >K6[lo*2}1Qk1h "Bc?XZ[θ/s$$Z~t)צQ-7)@ܭ7[M؏"%IE#rQ"b5Ws Jg'ĽR2O%P=D}{_~55rӇ޾zxiKHDLm2ҒMZ7!#Or{}=26HJ{V!7JgrivT7B^ăfޘ骎Wc0v ';17}7fݧp8?蘴$ a$x:56aior1z^E=)fRkBVo}_MhlWc3סMI18k 2CGlNu\ ʦgIuychX~u&_i~ݛV0G`HQN.YE,*7 OVWxL%%gNv Pt=a ..kFhy]kKDaK(:;L_L)+J¡[o% bjGp7Q ď2iӁ('hԚ-̤a?낢,=z[.! @}7wR(^Q$ӹ=(֝,ErҖ'2wVywη룙}pda0]h|e̥OƧOHIYG2U(4nuv~(*w9Z!t9~SRU=>3+! +=G&\(25/X_\#"HxCadlcJ lRl:`lj0g\ıHեg/ WUKKx.? QJj̜HZKD`c0 YӨ뾬z6AY\Vurs; TYd3} jNQOpb%U?T_-g?_t7\ /ؘ!{gmYϓ $M57ZSGрc0"-\٨t7F<݃$ѣ%]IJLcKf/}<5]Ӽ)!Tkh-!5wKґddW^,oQxRɛcc0dڛRCYx6Tڲi,|+(hKv6.ڋ3e դg-'ġS\}|:Ѐ7aα JAWoˢif}˞6<棚.c}@eh=K]GJdR?`ԮhlfL|]Dq 5L .s657 X VRu&~J02hsSJ ,'wR>37=Ld9(1V_7Ҁ^Cb!YvgHUœKN72{ X, 6COܶ2`c: 7ǂug:L< \kyB/lԭk,f .^.CرyᏎ7u. XC] Q%zxk)S w?GI3-z8YfUVh c'[!-8+-Z5W mbFߞ.fZАH v*frmz$$^0*%dI}@>OZ>+0Q E'e.RT8VF)Z U j&ZK='bA&l?z7_WY߲避pEJ)hAr9ue&܁yw+QӬ7@1 x}˜w6}akr ]pFSxiF b  l0=ܡk{8G7S/CWꭆJE\gNiVyQ64/!H;oE"as h]F!O8IT.r,6.WA,(}C +spH g:%JEdf d?Yj֞7]xRMS[ b^ӝ{ KwDt' n[wNwkNg(0Q1p#Fq ƺ0װ%_"p铰g3RӵtJ+pCkzybqM KbPE*:WW_7|wucl1Bi#'Qx}uOUUS5Fp?Gf.:: jePA# =ph S G~6TJ+ ƎbU\L2sqߝy#ȚL ͼL60b-dYA_d.~lL⑙C*rt6dq>Uh~"ᯚ3 emq@8"CЕdi&r$li89ᣎHz*s+N7 fք[Q9qoVng(Y4N՗!qX@=u=ҝQg`$Vd+Kr^''Ӌ]=s' q>"KX.l]]]R)>v\CGlhuigR-8tfg}FThp_^nl? |/C&U,w?cЃ\C<[Pt?'sR\ ط$tE/W0G-󟜜2ĸs4`-pz?NHԶ ˻ pOR"}q=QԋFaa#J1~h@%73hDL6%Lb" DyZfvan_/ddw"FNH{7?'v)\GĞ7}R0Y9~fo=3,1 sҜQسIe)3jwXsuap@ơJ{{ 88Wդ 'lѱRd>0E'_nQ|@斥 <tPsŒ/$g9@1viI ]ϲz䧰wObLpL>dt"6ɝ5|"!#mO[&*(KyS Z-n7Ob&deT@ziP׉z79vHra IG /zfɍ@+OUjүApS7ݢkz߰416w tB;}{)G1&dl Ìgk]n`#$>7a^!v"Hpz첫o*\pB99$1Ƽȏ]7Ct> AcpR9d(` EUt' j/rHVͣ2Ԃ2)W1\0RbN^Iǖ  mk(/BM,zصz Dt@l+#=B{K]+Ӈ >>ڤ?kVfs} IJ7%}p"/YZT /x({q^\u2 _02IP*/,짝4f{k#{x7~Txp`H pf00˦ l__xS<+=4'ڃ4tyZDZ x/sn3߉Njd.Jĭ7`u󶍚и[NR= J[?g嫔87=7okţ7WxM #O=FH<#S+ }bjþ\@nxyE2/.%'_QSiIԍ)ǴǍX0,dOHqP#Q =vw>Eu_Еa/6SDv[=~ 핎*!s! gڸQCIwsb#1cSd#c0ݑۆI:AT~k0t.+ˬ:@5`a`8(}ӅjDЅ_j<91. kw%Gdݴ%nGA ]$&mECAΊbyA JFV۪u!wNkƎvC?Xɯ]Fdb>e͆rں 1[HPNS>Éu!EP>]\PV Jᧅ#a@TTe湃/RvGٛ';V""GuC>,A7w=ϠS6&KPM?b84%Vf O8ktڇclr:͑ 0iUayŬz$X(~(D)0# %z@ BdiH䥴g?g GǓQي EՀv;]x:7{Ճf8U+B1R6YLB$Rkd cLh#M??eWIA^ ,,ٜL !ǭFCTǛOYOԨu2g]}E=2^m S"c/)bQP*^7V%4Hn:ȓ5W\ Z.>Xqhg1pO$R hGǙZM2؛pr\.!b8WK ڼ콽1;ZPkXhd<:eߪ)hk(_wqP{f3>Zb~?mua^\]L)cך]#gیϙV-3io)kYmvf*|lNhm7&x>X#>>`LL&D;dz0/-C.2ykx{9E R(gR|Ѧ[s'^TatònKL@TDzve"*+@pPOMTd}E*%*.DDhj)q?d5r*E+LFDH׉*9Ob;_]{õ;j{t>J`Zy ~V% i* ڂ\xҵgLEz dYž*qL`EnU;5i9_^%טhk#!B&01 ͭMË`qCBXI~QԬ!%Regx ?vf+`pZ 0lp*\ p6Yy(hDp! L(IL a;7|%8KS 6nqx<"zS«Ejº5FD2p{OĹ77avQos3CC뵚LnLE߀˅Kv6>' :]gCZ'8IfpDE<(8 ؋7ʄqUc نq) yrZ8JNQHdp)DM#a1,3zYQd AĽ &r=)(z}_߲RI|LS@o&dE&],p%](& bSOJ #*9|ĆO,'Ӽ\}!ehAZ}Éb|rt{WbL3fY\ܟ~`auy/T vV1O%ELH1=wL;O o}-[|19MX9šF}3F{awGrp@ >=׶ΠPEW.ߎ `1IGǂ7S GC1ha'$@wN9k|O6ƥ=np2p#ǥߋU@0 XWtNg-iyyeEGQr%z|yW7vdFh"=eK tث}LqlYx7)ԭ߾9cW141v^ۉgOWicRL ?i9:M_|V0]X1j:*Lf @S7Uav@;3=:lC9cӗE|$c=V8XqzJzLDNWweoHgv;~pOL-*D8c^X N3b(l--ݩKf\.S1?Tp+h @"))*2u첛_ BDanN׈qs;rI$|wPKх̯$pK^d8k4KJBh8_kHYCflޓ VeZzh~wBɿ֮Ƚ>Q0'%Zt\Y23 m%gaBÑ>g "Ї>֡ d`QzcĿW:uF_BO(i~MO4n,hADaJp]Hf63ڗ\S_l``ML;f,qƜ4pStԇ/KVl3j*Έߘ^X@PI&s aRؾ~>9#l.Fw.Jwm>W(-ӗW| S]eF !Y #Q D$}.5{Oj֓v5uPD`JH>©{8n&7-u"+%['a^z Z=j8)B+>i$ .vWZi(EaXϷx+a^"x@;237.V 4Tpޓ2mxջF#N*NNmп:0m~ښ81b~ VibkXw1˧V+E/c8„%Znk}rwwH_dA:fZyECasU\-}'rx2f;i\Q< O!6 _,֛Cea.#x ?<_K0))WWT7z 1,y7&[!:վYn:BF`guc*ZNweFFSxW+5l!d xvV(ub蜑Ci'f*uf47A~heMf:'/$]C.&O?; s-vb?cLS§ȏX`"@w0XKի6}a@[NZ˞XIy X}A1<ցlPĮ/ #{Al !@{};`6=Xq?_רom^W)H`_:Dq~!2:lLGLt)'ldb, fa Ã˘{K^3tʜB2Rм9HDӉnA:Bb%-XKJ5> :'iM6h!59+< u? `-4`X(`ps%گQ0o=kVrhX.y{51 MKBWf Ύc'$_wڗ2۪x#f̅'F<1`w#>Lp&#Nʲq\,1 qUSŁXv@aLUpdzSཷYUƒuB0[ЃҐ͌c;\pf&ϧH+G.Z]0{۠Y yR+%Qҡ>?oGX@] ,ҚH0%7 ϒ".d:*s6ly׾yLOf?,Z6g*OntY$tq+j^+UǻJS>U&= z׍"2NZ0V`\,b5\1 3wQr˚%[+q*MXJ t8}A|G tލVcُ[G9/K*V L)Q*I Lˋ7Q 匣ĽeRUcǹetyM?lg-ΫÖHe]ff[W*|.-'p)l5Kgsm T%޴}(H"v֓>a5=gu|r=Iw7v﷮B\eq}ĬUk\ń7h1Ur.6v/rxY7i n{Z7#vG284`˿:a # XBHrp|"kY@(7acwpی)B Y ܪpCk44g8̔HV2+E" ӝ?.<=y_}=PF-$?:IC5KxjvbwwbDU#)7 QxV&Uq M<(:%Gaگk~( d$$ċNwcutBmj#TA;3ò2/Wʇ_SypU3%/6Į\pQ^g{àPG2 Ax6ȁB;@iqVymAMzVC֜nc{kX@OxmhT"h)Gj#1kv6DOj<=Dx =3 LM' #[I ̳lM"ɭ Ra#Y\Upa8IN0a6A_FzQojY#kReuZrfWrWyWr}B=Dd IXEreHn\LӽhSgxoEtp*J'Peɇ90\spVZ0}8SF]I,4ЦdPJu?J֫-6c2uXqZYX@xXķ[t*xo0e t1Qpky}+?`oUPR$fywD1qA;&,3䙃!ßp>GYp=#lg=*a)%j[|4d]jԡYH+6% 7i|M'`^ ֋q%xAl!ZB A ua<~a\Z }` razlPXNNM ¨ Ώ O$IV!lU9eET9:pі\_=uh v4VYR,i\y#KAj7:]J%7*RPcmdM]Ƭ̧'ؽ%Oү<Dɿ =ܩޜ#e}?,-Ke_ͺbD7h<7/bcdAM[bA缢ܤ)p)="4 t@gDߴ(4D -:nh+O"5ֿ|{Fѿ[Aw*p^GҺUDEK̶s*(Nbґ]XBBrR?;S3 }?jCzZZg)ۮ VP{& _#jd޸ei):J,Ap@ЧtTjBq2W] !QѡS:_0nRP)-XM P6] 1*ۏ5gĤ{Btw;wzLȁPݘ5iՙi Y% +}&~Ź{ [)]T*4H y v֞N: [Kzs1IhO0j( u'rTZvj#Nhƃ Ь 9[`'ߎMW $-5V|Wzufl.V?jXE ;ԝC&ʀš&9R3yneFOeTJoIoowd~MU B^hoQAmZzDFGXMXpeH*nvk)9.RXND+h8H,1.;crL'x=ʾdl/A^BEf T/!+ȵ]は9 t6k0T@hsf?bS} )k2$I,Nٟz6j;__ܤjtWf V5 z4Lx@m<}Jy{;KXkPk rٱh ;'Ppd`]sZ\Cd~aҼtL-V*BdǐMUhm -^*rz[b<чr.OvCFa"VMB,.&6lљTw*QXk͡O|J_ /&R&<.J%1 ðmuXp2WQwUk󩳬Ek_ҵIWY&[4r!6*I6Jt#t.weQ'[ c ܁< ڳ 8ueN|:h,"|,vcz%& F\?X/)ЬF醨g0"=7W4:k!EoNa~ 9Z媱j͇1a$LDV񐔽~S8yT3cV*5,s&$x c{eT@ LGK?"w8\0)g<C]]+3ŎdyoVզ瞢HRaj3$Rkᎁʻ8js"¤o,*|/% uH6}7׵U}6X[aP GRjX'Uym7oOk9~fǶXwNŚ2U`:)Sŷߎ`}yK6m@ tO$vImO 9^N7և&q :/Zg=%4y@L|:rϭUڍT ׊8DՃǦa:]>\):Ԓ,@N|qt"\5_*I]S;aqI؉fJ`[歜RQÓmuhY?`nе`공∝owmL8%mm`ZvlvJ_y~?TgKغVqI%+`5_7UZ@ igAS&eJgԷPܢDM_ \ ]5LԄs+? J#ѾMR͋wRFv \QJIJHqޝ*j+0Az->[N'|+QDk,&(c S"ew`K{d30 .VZ8'hoj%/M7a"¾v)sxźJVPWwVZR3Нaj D1Ac-76]d&EN7 ,{Q,'0^~&Řed:yaũ´{dE[RME?Ж0sɐѪ6*丙xl+)9Yߤ9K'?pHNqoFD9#r]WSᤩi\ eSbrVUMZOcުe@[4+)LJwSI!UaX* * %<ɲHtd8`:Yc@\WD9U |G1պO+f2^c3ޤ]w$d@{:[9)z+d" ]:fXP,aE+mEmDAAlSO?+B]'A?TU :*# { 3{ m^?{`f+h[i608܁@ǀьqEOFHrTcuh @w&V6LNL.V.$Pm%ecVHƒ.SQ)#x[r#S ,t;0M5 yWYYCő11帓uQjC蒪=Lz1^Vw$N,si_Z,# f.t$|ݓ @Ow Md+!Kc7"&b邝P޲4rvI ^W6D%kkMu3ӣ! Y6+>1ޛ0c WvkQ/rQih^otӡ[VN |62}DB!b] M:/6rYNtߌxt%`lh1Oֶǂ_Xiu0D2Q0[^"NFA[-嚽̓5(e@źpBbjgp.CGO>3p\zΫ1#{xB-L_9zCT;-ٌ.ޟ&Ѷ_fcSZfɚKXB:Y@#C7;M\ ƾSiY R!juX:Ogu(XO@Wґ{ACb ?-Pq;7ڎVs)rYA KZ_\3-\k 2@ JΓwe5ٝYH)iym<{4`כy23ʭ);&wܞ:( QZґTL#FTxu߃ s"m%-;'eXhGk%6B3d.D8 0 \C3cEkF8?\H{GLups=Dc\fbuJ5$u8!\CE!>ߣD.N D~?O:j.G)TyS_:o2ȈΝJnJ`Ő PE;̫3(׾ӱ-C13_6 ppLalՍwJ,[6%VAG~pDS}ym}S+^̜|Hy.C_d ƘP-UڢA8>呒3\c~<3)ۂTB.O̹3Ew>[1s#Ŏ+ LJd{=v2j;nE&y:٬˶r6j X=!؏4q ,i ,NˡXnqWPC<ẛ1SL;tA1U_1#[Pbq#)Y7]z`й!P:&õT f&%(m0`$,)VƲgRPLrݐ>Pc-cS4 ѨID6HUyhw>_5k$gElMHuc{xgx, !<3j[AA[EN#Zx,p,TZ7YHۯ,˫‹ [3 "ӉgG2^hN<́G/0l22)ћ"cwIܝc/YҺ+@ެ5Dn}yTK_$D3<]PG`ê at,*80?3iPuSVŕ?{m8 :x+Ƿ{._J  4ء"[:-L=NS(vc_)ڡ ? TV&^?< +qܯ}OOxTԆ~):D/8Ȥc06 뇽\}}UG-GIê UlKj`3ڄj1j~IWS~+7yee3U9{󞮼ovxwy^+ zy$y *Ֆ Gf8à["U%7<&NQVziQ|QlbZPhkX>Mb°aȅGGM\ܧx9)Fq؜)'q80U슒8\?Gt#LII@mEK! QE[{z ?n+FK2v9;pm7)M3 ,ήu8ףmKoċM[);}E j-X=۹m;W/}#pܮ\q2 ±G;5ooa`/bP+Ka-O*#KDc6t98Mo{BBoD㙽 @P40k䃗xT2) zxZs4ٜN`efN*/A X[W/H άvLP7m|~z$NDnB[Fw'\bg\ooV/9ɽy{_ONy*E"1h=$,R>7qCD<4]P.M5<]-+FJm7P!'CNkI~[anE-׶= [j V&?]C 'O JTJ5":෰QtZDBoErfW>>V!uln* 0@`aoi%Ҧ<8Gv~I1%;^:m/_HH9(vt*s̆;9l{ڋ : cOx_n~[6.N#^-WbKkC6KFvwlx=K2d),G[X&E)x_4 Eׁ̽=4v-JTOPH :)uw+7˜wN[3, ']ߒ$!UuG;|-t6߼nĹH#rpC_^a\=){qG"Q;m[Oopw+$!ODWyPpAI sxhG$ T'%ySP V:zf2aMC3o#S nɛaDN2͵zL/ iC A2i[ReoGk.ljӡƼ<\3nKj փF0Ӿ<󰷐Ej 21. 0OѪ᣹Zڡ龥H^ATP\aej1,SQtJe$mCԃ)`_G8wp ǯqKe^"ױq|Ux0,{SfkƚK `,{xygFU^6FLbv *tESҩI_OTV;l+w~=OEX3] pnvЁ a4WIz^<BMfZQm⒝*[? *TLzۥBʵ3Js-kƋL Nsk#eTNwUFܔ 956۠J4/Ejzv\<l|kU[nI@}3Ķlıt$H IVUZS+y()8mfh-azà-H_QxQn[CÁy3C6Wzš?)ܜy)> #FfkF}c#AQi,GlS?/GhvkFl"=xXESX$@p +2 7Iڷwf{@>QFh=}7Q84D$ *{HG p z>0fH5E↌U]Zyvi߁F !5?TyFsw[ո@L-'b Nq?7&6˂뫦7Xtodi=~(.ƛڨ0xL: Z1~Wr]u&ᱲX`QpOи*h_qZXu[ 9xC:t2|cC%`ІP8#,- `2ŋuz@÷-Ja1Ѷ.m_~ >)В"]Qy򙘠_J:x,Hc&2 00 ~񢎀&qq^k4ho+#l{ԍ<@/ՐK# zlCb) :FDFh辡aqTN:Qvv ?ѽ7DM4Tv/ou 9u@yI\'xG7PyctlwynɛRC梊kHV!*71y'%KM'ks1h^uaE<{ |/P'c.园~sdfNcÔ踸;)㾘Trq`~(q/q-Uxsn 9WD,NDT "3ש}O3Vj+ -ۼIb$Ռ, \rC3ںmS_ l/isa>>AI5(#1XKCBob=B%ly.+\:z M'cL/G$]TYZ J[h]>ĀytQ%/c6$ {d/9 7jtbGOLA{J#n v!"gz&[f(k"u&P BdBݠA3Ҷ%k< @q [mNOBI1ZUI[S)[{t0%4:6XJGaf) |9El$ZIHy)%Pl'oPs]4S9SS.zJ9\Rk-֐&y %Ő!ϻ'RX4oIa=ո+V[ȭd{ KfBU#5f_eyTv 'KA"󎖟ѦcrM'yJN+FworJ{ʎqB)y$ܰ'Ow5du}lr?`>U3[ĝG; 1Iz.*n3P_t&{4{@ 7; @!괘ZϘi >rf9I]u"HmgJכS&X5yG*OJKȻ(٪l]owh62u4mĀSn&&[XQqq5zJkg[ 7:r2,uW|[xT!Ha{٠A~ e?=^Br,ѮlN"B(|Y6ٻ@pJfnLѶ[ΨLYPhH)Jchɾqcv@V6S@zW՗JĽ5D-?,LϥZ zކ)oߔyr mD?PNl@Otcl$?m[>z,+2ilsM`V~;sIwP2Q15ɗCg| fUJɔF` ;>Qv=òx8⎕[ orIf MAѾL A7DS%X1NO@N1̢Ig?{ORݗ67]Q )/c՞SG]Ux0dgGgae&/`E~3s$\D:AzΝ_gs3%N;qD 1 Ƶ-!-FSv/mO lѠsm6ZDo v_\ hi)hMG&ϾgKJ)!ux 4dh}72YY(#V+ݕmxFh`M/-])L% mdFGnYBk.^seI=Caw8HF#_ DPzڈJEҲ{3iٮWZ!5 ĬD%<%/z:U2Xg ?0_áSx<8:Tpe7΢W.fkk9a6l],Ihuכ\Ppqm\h-P 7ԓQPs/ۢ$2S[Mͳs+W5O - R"8u00 {0҈TB~Ta a,wZ7AC_$5jmGD ns*Gc$/#'_1TX@aXVDP;]wƙ~#:m7AH~Ė{{ϖ@# kE%%]5hXR0cOdwu`2Ha閗D'iR- Nz{aOɣ|6~q//-$jg1Bu-nPt =bqHXg %md(/EW]>|@76~k'4@*hߝHHv+6Ss P\Mƅgleir͚1PΖw"X@3c}rWK5RZ!% 4J+H5g?w5L㖽cfP }w )2T:;9l\= TҶykܐv $:*"zaflEͺ "-+ޖc&+5%ݞdwYgi}%.Np'1'Cx}DoZ{RZldG o2E@~f&/va1AUB[$(Bb? 3( j6VJ?7>|?ɓ|M<[\/ۺgeFbxY9P2Bqh  sZ'L7%r~^`bA޸G!|$~w3띔ON=l f;W##!4;0F`(k`cr$ggqIDAn?8R Z$4R3V׏զ 4gJXDkq}5 f|mΘ5yq-'7K'~)P_FQh5F]6ܟ8Zm>~vSB4O`Or \eX펿S Fm:ZnNݵ6,m )ԣv ݽ^% k{kNEkkdR-vuG/"sy&9nG-ᐱ8D"7&Jt1 O8_FV`@-sw["Qkg&fR^n@l.X.o(;G}^zyB1+8f մE@Q&W ٫Y|kkP^UݢodREIp)M{G!'yk$X tK4q:R<_\߮.ת@Es,]Eeoqya $79r@^m@TMΔ{}lj,j§UҸ]Zu:4:Es26} ZəնF%#x1Ocݏ+h*wH6TL,g"FZI 7lK(Ҧp]zrUqO+7k`Eٓr9&~&=E >e?,#io!Y?YJ"Qb<{Ddݕ"LMe/.%6;dd?reh/ӉP !\am7HٶJ}_E9 뙍pQ7A; WIF4h,k|3L"ru2kYJe}W e0R0BZk&cnǬ\c@1/P.ݓbf67UҲ a'YDcrbAITأ[a/C-2HțvǞ/lF_cw]8D=(AݳṇՍ\YKIH@do<]7@UTA-/١6Ky,&+Id" &*ƒieN}[̻K[Jw2H dH$]-iaHFS[q^ c`*'etMH?!:J0ԗD9%ˊtK+[X~uF_k zljUo‘uC5=)o|w`х z1c9FANr:v}%g|o]p/^ֻu.ݣϟJZ<C+F%|P<\\]f lb7  HDB߉d7#6k>-,747P]oGϾiag1vWR1=0z1;@)(UmP믳~$)XpB(B\Kv.]MU}̦W$9G("M#Aߘ9TGv{MAsg)і"|yenZu]&sjۊ6,l@Uy77]+9¯'Nݿ>0r꧔޷OWyq9ƾX}LP IN2u=Wap@>R-W%7N% %F Ou=cDžV$zvsVQ^Q˃X n_Rs. WXRx&X~95af4N4DrDll"FVkCK*myϳÌ-Z}8ZHd,\:'.MͳkY`š I99oz~- "t%%Db՞#j%b[CO8 ZHǵϕ _\?9QYy+>[}Q}RTR?qx"QauSP yKd܈m;ѝqw0Ņ4 USīD+<ڑ?*uoJ+ϹE ^r BO>kn -E2y}cEz<`,z@L :LjGȅH`еxk.x_@-;_d| )*P57kOɉ*EKSLc 4 /h "˖[JM([Z` 2]1B}{F _TM0^q([Rt׍vrtf]{Qq/=(NP2vLE v[Ci꒑~OE&j(*Y##f&%PZ Mil P$.3zWT] 1ut^:|}jzZ27f׾LCEjyaPӂnO4E"9G,ӼYcT^R9KB[.b@ VWohk{$PZZ(gt 3"9NxIh8BG_3} &0ޕc4Ips9zkR_kjm FD}x&#kNϤd`0i :^OzLO*?|H)d8hg~v%4 1<`A|eJXl E.D(vpZ͇~qbzNSef ߵeBѝ;獏(nL5#qE&O/aj "z~3+/>gquVhHlCV:?b پ?2O[-mMA1plV|=̝RN: {U[ᐶ͔].>E.ThX#.xq^N܊] |N5M NPwr^]s:(+i^lG vt܆WqHM &ǰ'MD5iq@_駖W9fıь}ŗp< DXayE:x _RdM)jk~1D*bcȞ|~2S)nHuPLbՆ^8lf2=ie"VdڷD>d,Ė%g-ɜ m2W.!/.cJ!re?7UƏ{ a1\OOcث&h'X7nWNh6s A>+_'jvd%鶗m$Pg lF&|9t Q9ӣ` X>\NA}F$q]] ͌~VmGjDxˡ_Gt̲ ҈mVo 9bCɥk&\.ܟ-hXUAt& KUk|$? ~a)NtB9]ՖA?48jֺ|+]ߍP);t3Ü"_ڬ?G\X'k6\A rZ(?'~srnPPllՇ~Mq^T͡d$ƴ󞥚w`uLV)fRh"ue+h\[o3Yr_I{h ؟׍}4=?W)>_4%'={/ 0Hgb~Tk\UHoU-w[*BA;0eB=Ӷb/2BH ,w.I ӟq+OOȵ v@ȳI(Y fMWw!θ' tȶ4f;+TQ1 gaA=;n2{a)m. 3;eAˣk7[֒ԝeCQx*CH1~)/)^ xɠz 7iף[XpIh+(w"XJC4?fB7]ROv'- V9Ȑ!|#OC} Q_'@-AҌ2`SЇEU_6x;Cӳ ժ&0d0I m=*/}ix3lK=: 5՘(H.:&ɊvJ( ^$z{d-z5]<[_)Ґbq`YG9!]Kx&5.j&Տsg3p՘b}f] Ʉ9s4VPx*zU.YޠdBeKun ND\!fĎ}iJxWKĻZ/I-!ɤm#9+\l~H8Aw)N!,Nr[A1}Tuż-Q&wm\Y\hP4fRJ喧 Wܭ4]ʔ"X! k,l 6bR -W*z`_%P;'v (X"CPXfZ}/Uj%Tݻ˼֋'s}Y)UFLӦ1O|0@gIӧS"߭@Wa$7(9e]޸UHlxt_8b1܆Nm\WU5'?"Qg$<^+'; Xs\0gw'.S_@;TPtV*]tqzD=n 4וx _BgyH:Cj'3mu$F?jAwǦ1Y}c߻rVmVk0FՄ|pWb>DM(}8w?5~DO^JXo&X |+&r#+ksn(w*F=3XV* ,0#^7^ȚvwEnH/9fdXY#8)@/*ؚ'h/h 3ڲ&}FMV) >Xn]j8@IAk8RKOoL; p>Ia'5`7k4&B ]fXHt1'z_pcOz|%.U1*p럒YS3QB]9CPu^0-jO4HB /|Oy4An*JF#<`z2X KYQToGN 11=ꭼM;!zC =$GKj%hw44zٞ kX[F mI &E^ /2]::䦦H!'nI.N&4$BBӫrѦ;y(Ce)đm#LwmTh,gAjq)\'3W?z3h'QP_UdT}, (IZp=j^ 9"v8@ȈR1oO(xTv#|^bp:b[ʗ@s%ZOs/A4'3[enA'xFrDUz~mKT]o٥'ԴG:kߥm`EWreNВE 8\39}J*j률Bdtu ȦTț ]ǑO\;@#. J&7 l"矿.'3kpb@Fp0wI5j9љ:;.m(ǃ*D5k*i;Zh [X_Wˋ\\ɗr}LxzS .+w:Fo;S'sRpO"e'}9ں )ܦ& #<že,(i]5JWvf3:GS,c^Fˍߪإ0T W݌$[ ]:Z/_[T :<7@<%̩U1m^"qlJj~@mujmT}"FiOI H#-%!Q\k9%ghUe$65>]3kMsMcgdA7UKz3}~.;c̼S"W['SYeRmIl{o&rL$b$$s%V1*R(Z Bɨg\3@<n)J-s:RvS!@d`iMJ0W>wH|D U5)YU; k`QZ/`I%|>B(eZ6Q ACzJ”O tv޺oٌ{(A8P1&èG㉕(R!:8c>&EJrA7C)߶<2=C:u3-}_®쥔}𧓬cV`K!=[@3LAUӃҊE{ӈ0-v`xt &6h+`燃RvK=; }6FvӄpKqHӮa%Z8Y8Ǽً0B"RA2\} /]Ha#1-G҃G)Q>jsnlU4X|k>ICjKq3ЏB1VGc-\$,BX?xvo_[M^ p#=͘_ڴk n*k kܦct"׭q"%^?szW5 o VfXc|y{˖~\eRj6`O$[$@{|S\@kK9uŔ>lp3;uip,B# Fg~ Y7 E8z)W _tA$, ?؉".ţ Xv[YrԠXCժ?Coul,KXi:M8Э3=4 @~۽mCgKNbR$24)9)MWLHR@۳ݏR0/gIcS j*~KVt7c,YRDbB$ZcS:W~r݌19  >n $<cpy Lﺴgd/q^L5Y*gg~ʼ31d֮EE |ww`lK ~Uèhs ;wJW&8a™h/M ؾ5Pj»4Wc@؉~@߾'d(PgS?Ex7ޠEY G[ 7ÛwQ""2N2r!@ݓ,.\.v (_t&Dm^X#JZ=I՟rNMg]rF""+Eh䆫8">\(6%U伯t3FiN*ܒمԲj\Iy9\>g'C)OH=`0 +DAfqP_vlLg.ߕi!|У^C;,^#Gfާ!@6g'ʞAv]\ JiAaO]aVi8Zs> k,Hef%>Llm:nFB풢4 Aiddámo"pk0_~P5k?&]ps]L`=۴V]ͼv-u nB↢}CzM@91MCnEo*Ԥm>D%cS{=Aؙ.CO]q ZH;hr 6ejMgϪzPR# m(h͝pX/?7Ps&w&[O#/[26NG3ޣ{Re/C_@o:H pkD=_Ѵ[v9 ],r9fE6ԕrn@T2^,79'F 3``t/!jFn> AVjd& b{yL:sѺ>@vm.~\ygn$/L|$؞Bm=((h<=AW&{ 1:Ĭ 4Icd].UoXyJk'=jF~:,B3*:)T;Qn+l A 4 .4=*esN~<TL3nB0%ԬlXL&wYMdH[O"LkO0dLzXrmp[g2< $9 duM-c@LN#5յIbP9v2 us-Irc&w.$p Jkk$HCYëe{_򕸠"7J]X>={|4\qЊ@Njؼ*^Rԓ/g z~[(@JU`Aw/Ͱ1R5(+Wͻ=,Oqs6_2G51-v:_΄10mtMaV. ȊEiPGo@[e۶"q4(H 6Y5șQ!M$ͧGz^PЫHr%g)yoa(k"bm+UB]GQgH,efaN,j *g^:Ǐ!:N8.22Dr ai0{w 0-Jrț./f1\Xrs:`(+wePW,kU8NJꤋücd yx!aBj\I!~3g:G !tI+#OȫBerB/&3T&H6u"^D#8 Z p/yDzN<"L=}a;"y>B=}!! dAN7h* N;*w'|xln "Rxہ)i47mbӝܵ4 )xNNnRZCQq\!H{H1n([h:HaxLUa)PiY2džOʭ[ (,{{b(b>j) ]L9,\a&d#|`jtg>AL }%]2h%`yd,^ eO[ [V}h3;AIS0ܬ+3s 4b3t-!gR,eSrVA荴V+~smc)C~YP=wQ-:P4 $g !sدPX&4;ɗd9r)p.mZEIuPD@*k, '{uOPSqi~էrT˪Хs$rzm8m#%Mۛz bM| @W1XQŠs?F]B(I(TqFIסnJ2P% uB__%M}XV>e( GЎUDKH`ۃ(;|ž_= E}VYzj'7?f]ԫ|HIWptGas,͟FGQ+)5H /YS9A.BÑ<ncLu_lg뽺k)NaK yd1RHC9w0m6$߁F p+Nhp+tF´ tB8K0(a2ghk^tdށ &:eסba@;Tbg|r8x˗qIL-)+a~srݕdUn_2\i0~z ޑ^Dd/.T.DoL_8_`1_]hJh:~ME :0]SׂHP0I2ŢDB@u?Z[]#]= 庀 'rj`ݚ!\[>G ]C'g8چ`|~|݊*ϲT[2Ƭ&A1^ ŧM$No'l0l&5M&QȽ%@WTAf*..Ӧ*ct XqvyBB@32Os 'QF"{Wk$Y#D#w/6RfX4SXDaq 8߆zڿwD8"z~ʱ}nՋ> V]Yfh?A;wZ%$_> TQD =˃i H o`p9<$ϔ=8:|\OFs|쫱ye !14|r\`bK͢2l@oJ %{+/LŖ&\~@4z`RYrߐn+l7.09@ZE< e|KT*NC$cY9BeLF*sS𕶮TV6޻:])RTB%G: ZʿCe񯢘+zmܥ_>j&J/7ۢ)՚ hiR&oQo"3HހWMmXuU 6b]>nqYXO1V!%{"gA^ʔ[^wL#܉ߞ1}O!v']{ַ5!drZAW4@r{8 V(e\BQl}PBK~r|#` %9Mm^ECC TR(ۄ` ZT%/O F/w$bb 0yZdƊ/Zل2JLzZVcTqz,.\sH3rܳܡ$r$k]":bALӇ kV aQyJ\ *X|Nnx "33WOxQsхn;0z!|485tv>R"6I]-TV;AK)HZj>Yp 6.^+φ)Hyr^Z0;ōB&Ĺս0 ;5t\|oiYD١+5%0MJv> } 1W\!;uzdO ' ZFM4.8C"^a Dz9Ds@Ny)ˊRaI̙|Τ t|Dįq~ƨ4@!L4xCUÀY;@Wl'1IcbP<#חiͤHcQ Q6V `۳q@SeAFXA9.dI\b_hP؉ݑ$D 3e|l\ϧRl7&{|%0:6\!Ͷo͂t%yhxS̫ne>4;0"8>wbm5]~dg_W[,5 EhSW9(F,ԝg[&O<`QU:pzv繖`Ir6/RH+K1`=@@OE,Cxn?厞͐.Iu6rfRܗLKܢ a=gl^"UY=lUoå__/ܲVdʪa#^n;=cbw*mƗ> jKndO)$ .9-=~v0n? w"'i@\L&]Rest&CfRu4 G Y$z %=Hܠ fdA(lϋGé0Y~'AdY -N\'<ΰZ,DeG?TϨvmM4mgEcw3ƞh'1_z&[e蔥ej QkAޥ<8MlEWvu}g̀/^=Kdy;LIu`k}0sHI*Pnw@/PBZwv@G%xܳLEhE@ox񧁡ΚۦG!C 8qmBUvL|˯b6"ޕST4% am]1q/qa2`Lh4Pqv/1K}DL qV5#})_ٴ"*]ntoh/v}{If}wZ9PrNa؁Iβ;TaX;yYK7+&LLQy# Z'&7TN{ɷ"LJTSpzZP6wPT>m852IqY0گ#A&r3_55JZ\ŮO %T'?rR_R?,S shy,Z:"%)[ϭ/15l "MpTU>T3]_9f"G&׍ݡO^l!8?~ReMe1IR_eg&u J FO c]ibwWRd~pFqqԠ s~hX١zN9+P NlTZ"R'TŹjկi C2>xS[R2KL 0(EvL4״J ,'l sG\wiѢU8kX$6lߍ2Q ~GWqo vohlTqY|]] NJh{L4ϙ 60L@hcjEW[5Hy ߌF髿ݠľcpw[ 񊶅<{^PP hNÙdor&a ?&Ƞ<[L%opw)aN߉^)Sx\@wGZJj7 |Ai\4Oqݎfs C%zy%,B.V~"5 D&7#( l*hC URe;$+d!%bЬ (;j )7}!Q*XBNJZaB鈂-}~R&T| `pÈA8E'ěnISQpx qv ^uw̬q~PsjД?zЌYI`$`y$Fm`ϜML44>rnjT/- /ۙ-QE5ʮ]XMdQCr$[~;J uIгPJVz|dq2`9C\“7rrtuh6 |1*T eq~8P[%εtX;3 4,oaD캸B{I}=**xP,Y䒃e^SʆWA񻳀4wKxJQa0^>DTk4wUpCf'`o˧' %`X4#D|oQAݱ҄m˒H5poщx}/Tֺ ޳jfBK\VHwLDYRΎ#_ >j ZpH얹a8:IrnrW2r7]NrQBwcr3kjYb^#zXݻH'`7Z{R.Sv`jO_k[n$5?M ҹ7Ú=P_@JI/2.S2+@a(Zng# j1 0_!uR+g߉Ziٓm%l(qBg/$F:4֩IHE)l/9=XU'Xl(N,~dQ]MьVR0"'Տht' e4tk+eհ@nijGϒ.V'?V]o@(XYE İOy̵c ,+7;Q= gegF,Bh>:htXk Tḷ7j"׳ޖzON?C/J,S#ֶ aRB"Ҡ3Z^'< ;Jg7%EZi HAKБ/O%R00((#Zz%'ȄˑG#Z sYlׇV4n駈ڜVl#GҰUrYSGK8ͥW#7J/v*+&qF k!tc@Ǜ1 )S+ɥ=l,q8r8b{VW\V%GQx8?^Kn43jt|LgP399MX;ϿP ? _|m"yyQ tp# MǷJCV8-P(bp\ő$bx;BK,Br% YMzGR1\Ik趛YC@d[w}r$%Y3`oNC9#.GkqPW9dv8zy5X~R'ds2 9%'[' 4 `v {6ӛI7 z]) `MU9-Qeg }6\ ɠy #_ܫApu[.;kA%_:31>eP>JRH 8B ݕMKRu)Wd B jy_2sby5njELH! d6'LApIψqsBKᱏj8M09[vǿr;KMe\"D@GAr{R$mY|,_+*QN#7cFKf^́%n%.E_&cuIT^kDZs8}\).@ \otQD݇AѢvKf;*=߿ Ʀs=`CɼG=m0$,Rr"ս0+'%3o Sc(oY݄ؐ)J/x;BR)?Ve{uyϛc5:'7z۝;5XevQ')CKjhM c{d O @yЃ̋j_VW @jsچH4'Iܘ[h߭=X<ø2r.b~yI&&yZPn45GQ XTj5;˜{mw2⅁2Iol RC+5I~wniQ I~Z}8t-U S!lMtT 9< ʆ㋰t.7|. L3=̔%4?g-cTBh-i{ >XuYtro Q%KRg`U J.dgNq'b":^ r@i#j$ `pU  ;__naҳ\+V}[߀ŝ"2TÛi_})a衦"^^ۋ> a 9h$㤨w͎ˏMoX)?:{C4n t{@+oJ4zj X$p^C&D[\ gc.K(ύsNk.'Jp!D;1wQCm-/8X6#tMͣoG2NSɫΓ:Nag;!q<v,O}Vkz3Ms3̀ܶG@ рIqHD!zsbKX7t2r{&k$L"e467I(x $4a EQhY+70zi D3(A3K'52 Ea8 K6#naH/PrAGY%Cc*+jl#Ӕl] ꝼ\Oi处5!,%>Қ1&oEPi@Mqird~rn M gK-91}eӽ0c-grxl+(& LO7O7vV,&I SL;ljJu C3_3a+~ s,#A:?_y)&xP!Lіt|YؤPVҕ1qxcE)Gz <`;L$twQMlǟ#Rh4hAJ(y= 7nnRu ȍ^/<=s Ohneh p\PGF-L\b|낮d=~M1&;%N^txϊ<٩hCkJenҭ+4 $B{: ! '#ox?;rK$LFBgElgf-xnc.p(b#:V>t[C7-Y3%IRJ5"ǎazGwMs*H9&cc#AN'Qng mk5RvL̓7Ib*ThR41JT9NjVJ(H[./dp .D\TH8FT [lGub͚cU9O%u'3bS_S9'E2qloC0{̡b5e<5Ɍ!8s z'WAH9%XdF1t-GqNGln|> &đ\Ȅ(JQּwlb0VډT<%O1kTw) 0x7y}NNjx7vdnНʖ`gBdɯ,֞FqZk 2'7iYLr]&NRP媏) 5\B<뙼׺f5چn<ex 1p9 T!'3kǔ 4~E> ԝo< ,"Mҝ86%__N%#(t݄8G3Ex&Uzm $ L>7 xCŨʼn?[P}r$>sH"@>c0}uk gE9xS#$$%@}WDWC:W٤ ;_RW|iJg:_SJpINv?9v'$N ) !Z/^ ^q[Zi}!6Q`Qףc-Q&ŢWk? =VLdaCb/?*J3P˲ 4 Z{#F%T۴At˟32[uPs}A޲GYU`7. Hh,볼%gi^Zq5nQ3")Q,5oUxKn+guNda T[9`)+ù 0/┯Fu6Rc=RzhP;*kTՍXoUwaܕ>(ZI6ݪd7ُJA$a,[w} }gQ1Ru+6 T7l $6e.߉hۣc5n"싒d'߇+b{ZZLG| FLx'F&]H>%G \Ji֬y%G ]XE&yX?8WrJEXA%Boۀn"VTM0":ُNM?DŽ=Nft,k$!{F\艳6K' uDOnȳ 6_`xx:]a ($E+0)~|`-.h7kmuTz*~`|c7s5˄Su^}R4U}1U^?cLv|QmVV巰mRpM$`b}{20nEh޶H3D=ZלI4^6t> YAɃ&!Gu26Ipz@o?*+\`Ǐ$9|< CX>(ا+4<|ock|)..hts- MܾQǥk9 ?=oy]3'o+f97p$*M48I>j(YU×n}Dp{0+Z !7|ɳc >TMP⊐1#=),ԃs4am+1 ewԏp<obM=:qUю_h^5t]Ѡ![\4;;#H=/Jd<6V?{3?=;kPS/yĞ .tїD0fjMzUdd5кX@08W|ec}JreJӳ.OMgP}ս}5C Na>Mw*'+QZ^i59}ucd 5B7HRN^TFKeͪ,5 &oPvUPbӖ, H @gnC>REoJ&{ڦq.8{I %9"ntkP8PMW(r[Ex0mIE~SB+l[ZYfR aD *ÊlBuiYU9EjP ,;ahHf9, .$OgU[?zђY0.nՓSu+CfKVEfy0r`X  rrn=}AqL)N7 obېb!Sx`8:ӻ 8ׇrüoΓ?بpPr(QsTB*F|),=:?<$V/ 6y3:HFB`()Bn]A`{m7%V07Cx c -E y=d\]{aޑ' PoQbܫeG;fY|C)ڕ 16Es ,%_GZspz<[?#-z7ʧ nĵ(w1Rӧ<\(KVJRtn9C.(;Ќ#g8_`- "x8Z85dFu b^}qÔ'+p@GTMBw)Ur{P!g;CB!Tb.>q+S{S=G^Xs? hr*6Ve=X[peH@:r VZ?E?έwɕ: "oUcHI#Ӑ1F怒am2kzߍxV 6yL gVá2dz)hn-bZ`ǽy6"ODͤ\ȠӻB1'2:8~i|GXtaL5dCʻ4󸴙Tdp[Q셅qQdZ"ַc.!8@ϵ<)q˷B-Glwmm[D@ׂGBB*@)˸H:NZcXxT{ >C-oLK8Q8Bg+wLU :"L=u0<~my#W=3wJ?{^_?zzCKZ;hې!l`$y['-А%lj0`w kOFN:gOxVH>XK4>-KG~|G~1j@Ԥ X:[)匱*@ ] z=!֙W,OAcYTV`#[(P5ӧH P9|}a*@p|p3%3\ ^D!ȵы嬞jwcA% M6Gj<~ܘ+ "YDaY*+Y%Sh!PWua_+{aSǥ![UCPZHێVogX 7pO/W#)`j$B6|BBB^`Id^ǫU|xؘ8tX4ܺ84/ޡ2Y pG&&pj%!&pXU{sBU?x+j(`Txn>^‡8-B940ۇ@@Q%wrF~7{8I,#I: t@!{) 8?}6q&Iә+yVwVM`oxUvVI]`W~!idT]RB\Ig213C_6 8Eyu03Qf7(=3L~[1ikaXP.nkr$~~IU* 9/w@\޻|0Y s܁'R JG/ 0sLv4pLFI,L/eW!~X]67:%I^7N򀫸,DGҎ~ڝBo&烷LpsYCa:[Ck˸S~"߱GdKbFhT %zc?%_QPM)qЧŴu:˙R41&c;;`q-Fװ}YaKqg6@_퇲Ȝ+RC+1>QE kKSl;P 9y\r/(G2_D/8-9l3 l#JO*pNHr)![8$’,Eөe/(\ ŲM/gIPãwԐ2&w ⨆;<hK5%+\vd@]VY0%oO&J!Iw#)]:'l`^ <'Ca7y|1OW4q WyӪ+<ŠҝOʌ6dyqh"Ȏa؁JN%;H6yu^;}KvzzjAUVK47kW9ø(Lb ^FsTuo:z舺W:bf0pj8E$D5Lnie?n XvNuߴ4^ `ka8PAXĚ.)A({4ghtDW !{BQv%8s%>%o.~w#Qw"~ O ?,iQ;SHU%2@6Ҍb`f*勒h$@Ȭ.Y/oxzƘ ?_W 0?)0+WLJ$>eL; z8~n?&pW}/O~}>j.#`5\ywGbNoS=x9y&QB t|37*(fGB> N&({v<%}hCT 'M6џM'^!xociΰ?rRɡg4ke_} 8i8}#n>l3hLƊW͞Y}k ;\ic^Ȫ{"BdK 3%7JOcZͫJ 봒=o1~h:膘`v??-$ =LG2X*h~[Vn,:snU.F*w-JJBC0W?\'_!ʈ/37M`#U5Uƺ@Iebɕ3kO ~|x,GFu9>[=ԸH|Y9b bҮk=a@et?C:z+?qQtJ_N 5?&"&wR xc`FMJKZ-XU"URelQ0/ɴnnI9wQcx<2_d%l ?6]˾b߃aۏXC^GZ&qpMlyf|SYނ]'F83%0  aЪz |3B>guؗ;ŋ*]kE[V.94AgBP[cbƂ3<#йs3Qut.h Hl’ _n}K BdJ4<%Ox{i )t^!ZtZy'KH43g@#Il~v t"7{(Xg4m:1l?ků0LS? <'ѻYW"P[jc )/޾HM%faS?,+G4gʡ9+#_ͽtg fʾ U;܇p< C*[RYl_RZ}` uyb/Dero0KVMh =[1gi-{ZZ clP<<;Bnr/'g} c AYW'>c"GpⰳOc\wٍlgN,.Q>Sm$$iOٔ%)o]æM +S0EU(ߒt,\%'2o7KKH`r8KcnAW-5lw^㝱qٷ6 dC>^'r,w ŇA0$5䘕A2*R{wg*pB1`L`"!n?SvZK2͘7/ds~Hu)1r,鬠~1@kظ7t=ţ*D/#{~-Ear.beA[R]뤓g=}~b.)l:Dߊ'ݠ-D^9!` *~@p r쯮yΩUa0:vo2/Wf=Vf[*OV8>[&DPY9?'  p:Jklx@=sijpI_i R.ڀN ^ّ%m;3,U _]uoM2D`ǩ<&\stG&O 3>XOJ"G;|u'42kba[7a']#24*[v!'&Ɏs&lY>3g_pnKQ /Bd8{z+|_nh,~D=ֺ`4bRfuCL9Z:l1$bE!B[+hIK,eEl$bEcڏ?{@~ Z&G:PT%tX1T =$XhvC \7NڥBO,:@f>Taޭ%Do msK|L-F.w(T8XrlxR7K ; 31Etjvw9a&G>p"sD0|Yq,z(CYU06,$U 2J_ښ,򡉯D#Fң}ff?OaE$) ? 4,(=d0 ˝ F2N~ .8eH{*xx,0 {ݤsrS . m4X&D>q\gOˤvn6+iKQx (F}aT޶G-c@zjW7`'z㇉.3CtYizRMf< 3bEX<.@/qRW N"u]l?[T>$jfiS g7 |ӌQ>)]_A"V_!wwrkm3ЊDz\~ÀwL?;w ,-]`ր]+اI?b)]k-Rw2p$(s3gb͑'֛7bL.&#)#V֎X0'Q2Ep ؠ\i.jH hjs\B{ J{B(Y 2]IVya tvՐ89!-gs!8:¤ymAp`էs]16 vscQH'D,f'!0sQI o^E1tJ|QFCcʀC T|mPDK$F4>\p36pЩ[b;GUWuZ/)1$TggiQ%$VbPyZg^8\tf2'c9mrW BF#1O2 PG*d4ꧦ퇎3t: #x[q"ݓ^ѹkWzxCDM=[ފz'UI A`B9L%e?CghoXxF&۵f*lmA *L˼PrEb %*7j!R|y0qI`(-kV[vQ(g)c>qF 7w\v:-p9[.d|54S."'elHZc+-~)L5 HV˩Ϡ v&J(5VXSz(D~lD_9IKuL2 |F #]o^p@)?p~^ϱCM , F [f5~ekVuo]E >Ĺ#mAvq˝*~ @b#f]֝.T 8z S6،m9 rۓSqb@)VûxIq%aia5CkܔXțzM9d,StjD37*ߘ -2PS;Eg7}- K :o%a`)8 6zX1\Vi cPI̵VH{_?C0b^7x%%slE4\#9aue+D,.{H_<;MXk|]K֏j7F|orb:7),a5Kc!| ʎ#hz 43GWpVԊ1UX+.,D|n*S`-GU3C O[׃p"M뼾U,$r[ P>N&fE2˻w-HC4{"QO!koq NPBd3< sR_@'-ه>h HTl$t{@`%Li&8p>PL|uE6\$o RSJpZbj2Pm$wH )v8*ezIa–f[$w^HYlj&m(5A mVD>_p|k"Z A5x;( \d7nW`ɨm3}0⽴ Օ".Dw<b< -yW%F$'$-Ly({15o~Ƚ 7 3˄_v+bH@@v5z'Q4E/NɓS%tJPAyC$83I&&LO䖽w7yݼiFAS_2e\L%eF3FdciV#hb 8sI{.77\șbQa:«b`ȵOLM>'qڐ9󕦁fX$QI_6db#)i1B 3(eM_< lOΕ]fF=e v?/} wj]d bNFMF o`kY3l1 VɩEEg:~"xhݿ 7#{}RcZ :eo (e?!+u_Ik36r3liW|Sq@vKkkLuT+Y;Vti="\] @%K[aЗy^ZuhqWgb )\ ]Z͛?r8 ~Unn/^b3ξDNkӥy4yp;)G#~ʌ+,%;2)7qy/z1x#L А۾`/TgӽmT=("H X-kR>"vc!++e}ub]DY],mt#ڿQLe%{FHڒF>Ձq$:{X*n Y:A_Ƹh6%L7'%ʋ_˓3,{J"8MԹg<?Y7i3P*u*H%Z$ / ǎųE`Z ?B]ss@&JITwbŴw2]lU*.ֱ'61 y+k̒ Լ;D 2Zjrwxְ5D*nK90ث2h)0#+c*ͻJ l36gl_Ywk l\^upHI~Zf_ʯ (O5ʃϑ~1'5dL+ I7+_͂:> }5S^xpq7g_q8b\=MM:!-x w.K;?aFf!33h_b*sp|2μ +A7(l4m@hTJ:=ZDk0mǴJMتW5 c^tA1ڐ?!m)-mBSMoP:Ö#`*I?]!HLJ֖? h\"l}EtsqNӤa#o3lϥ>eIz'Cَ 'gln1M uŔ`6q:?|Ϭҳ2F PHqϗ>pQ l>zgNI[f\êo{xu1}bϞFDم$)(m%̞&N#Wrw Mhg&cZmMS2y=7*&H7 u98:5a.<“aLq+et!説8ag\q2%Vkoua+Vf23nۮ4`bgk!qSӢe+M'#"=_NK|de[FN赮T9Dgy)ZY=-%czLT|q܀j"yY\}OtRsRʠUDyR(/N밵\c˕q^`DbVw|hec&%2Gt;bUmRnR͜ݒp=\/l_/6=&Vd\A 7ޅиSz! ~:lPn`.Q0~%# iWf&$zakKb\>qJҰlJ_xmRK':=@}|Q%_bYPu@ >7K*vа#0t6i&>JA{t( /pht`w`l&2;/&jBatzޚCE94R@@cSJljVP:;S܀fg\lf#ƶ|W.?VR{}QB,}-5:.Zn G+ K%FV>n=?wV'TV1'TfF²Bۤ9!45ɛ`n ՎG7 4XGxI`l%JjtP?Fzh3f|EM*s(g='UbS^L0Q!Y1 yGV+ ?=~t-bPrNoaxr@CD󓯪K?#`^ht{ޗiB 6E$:9X"#&\^R;Hy)4>}~W/ B?xxo-joW$Vui\1GgJ|5M5w#ӷK~WWeXE8; &όm?5v8|y=@;\𞶔e+'F&g{5H`FbihI:bI툀N.8t8A4Nf#N Џݨ|GHj]X54-X9AtFa,HXWF*lZX!^ǀN.` "~ rV/9pac+׉}5c ĥwΫuQeMT&!b{ng/U@jw |/Q-#竀T`8i0*=0{hoV%0'6V$C"~h~̋m&0\tC%9 9l ;LjV䦙^ j5-列+bvH&"e=4εbboE 28Jryp/ԘIgxAOs-0d4pkGJ0U68-3sMg:)>vD3/$NTXQ;DT "*'zڃV*8!xV^z- {a#.^kpd#zqK1A_HI/~c{k㪑&Kw4=!l? (&.JGiHR0!D,9Ҡ?lEd=#l+dliMqɫvbھ.B -nal:c$YV6-~NRh=(/b4z7-l˦Q{ fIeۮ5rl䜗v 㟟~|;Ql8^X L^+Χuݍȱ:mW ޱc^QaH۸VUڭ][ez8 kn)MP-΂l"$X<(%܅ Q]VIw?$9B3sjՕ^ϋ8J eIOZ:\/jl~#9N*Gea?9r,Cml!~ZinWWkxiZ~ҵa6큌~8~BYL)aOJI+W^b[3CA\A;49(-BF߭z,ǹa! bWH~vwF~wȘG(iƃe[nH欭 @*&=B!Q5_6G( .,L[h?Lf|2R^W 1kw+A ߡ˖ƫ8nyzsI}'!LXb5aV=ڢv:# /jcl޽/94Zs54bys#Ղ]ZAF.Ъ?WC%X.S~oLj@~69?eψki>7$$7Y |gr,O1_aՁ+XF([EѶ#Ї7cFVhQ6iI OB& ,:!Oiz6Jc3<~_GaI2l j J-~X䔥yE%ǟ@ZK ^NʇxLPt GLÐjaS]DtD:2m< y8)@)!r7f%7Ð*1ilIDU彈&+C_vf^_9ZjU? TH%DY?4s|.0{R0,#p &4@l+Oo5#ª Lpq۶Ľ~?(GOcrm@OwsSQ ;s3{ 8;<"n‹\ v㭑dЀU,I3TFƶwv$ۭ1[|e8ɳY0QA/ύ?]!Psȿ6Y˞C>ŸH_ۉ9/s<%$ Kk# N~/ȧͥܶ(:(ܧ]a_U/M\g%2 WHHK& |N[Z^X@_;ln%g0_x^/[r=>f& hPFݛYt",ʗ&H!i{QQ !w~Ǭg8CwGk߀HbNn{ ~/%)9*^]GO.y7/ TI]|6B!$Kka)foStyIf׼VR)\*2(\:x [ҠndKv|(̩$ؠ^Y;멘"wwŮ{]jr 8ªs>ŲE\f($=8g#AUx G 7PROEsnJ,spb%\˺t2F5Y}|L ($QE`ԇ}E6I0F v)aheRt̩;]tO`Mqkb3vxkc,?^IAI| >8'IS=yμNM7G^{و+ ~IW{/͔E"(ۨdԠhl)xCdebO|?U&T)h MD78 d",Wobt6)")ۀ!]#u*T4渝@-,n*0<ٺo-ܼWRyXr(Y߀ShWJMZ_fMQd3KQnq^1LTbw۬5Mr +DW~G&cp63_"~}@*'ѳen!hw *˵_N6ON('*̐c%G7W#+2a?eR $ʨ3 e ~pL dv5q;{;%Z'-~c5SM$U(r!# d߫O-@$d C HI=]/y,pV^Ni֐qEҤҖ\;<2d 逖-QC}])"K$E|z_1D-!5e$OY M"@vE>pvKB洏ÇN$VWi^[,FjVA.Pݸ Yf:c~6J*HzZ%@/"@ز<7Ay~J)P0b*Scȁs*NPC{q$%'7BJ« Ql2Ͽ3a<+P)֮"U6~*Q6wT]L,)|%n.(K%ȑJNa~*H}!p1]+R֤L3>aD=W(yI(<;v94Ibq+.D)Y J=C8@9JsQh/*juwYXg&j<$$5vF cr(\0ްSx=QXxMP<1{2?<}%oQPVCd;gi^ޑ4тF9__8g$|coAdkiZQw|l`KTo*6U% y_<`>`D▪{Y/8'ȱaؚ% >}W[?>YYH|4q8 ` pxl^+8w+䥵ź{Jf]Bsw'.4|=ۙ1d];YW]Ԯ(ӧ giqDrL2V:ldcxQ߼q7$0v,(:YM>鳂COTJ}1tHްâ&^Ẁ'n]-HӮ^hʿ~@׀ jg:rN2(墓@Cy;&涪ג/vbm1Udӂ/o5[fXW5WBVd(l7DhKJ0&B7#p攤s/}KOzVUS̝V[O6tr3Ԇ IEaދǏb KK딡#қa܎ :b_LbG¶HHl/*]!pfPg HG~f5$`*(`RRQ,րj9 QD\ā᷅hD%3FվB41 ܾΏyVB% )8rlmLtVI|#.x +IiOũk7uK8mR1hD= Wԃ˙?7Vh<3\?zI>H0mbh5ypU+ofY{q#((Y2ϒdSs{ L d^l嶳`+HE{"!Mլ+,]tJ! /95}#xj۟,'C[fxbYu4=Cuqoرw=O3n/A5BtslPfؠK A?Oe]+@A+@roOdA}A'^C\isغnL؍ ׻=ey|Z5yiGH~N _y}Š;^civ#qH>"MCa񐅪TKDwUb jAj}E>jQoTN2M0+._óA:5V)-)o^9c)y8=ד)X6Ǻ*&3sD^=o;-7MA,6&Ԑ cel.;ƒg;T@G¸AËeoKVm0HHr8b=-^1L +Zmmo6ïc%sGe &5CrZ8TutN[ ::2cݝ$$G"ѯ\b?:3J==ul2˟G.%ۼ刊Y]-g "cmmFKӔn<5?e)IRD֣Y=fY[Ey_L@ԒtJ膄bf8:l.q2D|Սqz1#z qVBs6A iYd˨DOө$?E]);vb' }_hl>V(Y98,ߐ_haҚ݀fY1=`7p7l׿=9Ci<Ubz|ɉPNɤl15hzQ82sLb4˷3`uAXChH Rbmj?D-s8go( 8ӱ|KWk8 nI#&e/Lf nZ{ukPbc?E=e|N.I#10jS{V+(/DN' _NO[$Zȍhw.^)6ٰ߫_I 넴/]=|(h &,)xfTL*u8n2)^xhv0`AsǺ*%'ΊўkV8F{Q$:H(ي+8,s;$Ce\ [zvho%?jB0'+1m<{}cA7B Vqyiސ 20Q\sۋX-eavb@2b ~0w6N\^Fi -Aw:`La4}]X.j\B*AKTj{= %q61QHlǻ:U%'Woi ggL=ak @)rZ"Ct;  ap} r꧿,}1pT; (^2qLT:PKQRl,@gw + `V@vf~v|W`sqYS]/ 'cNxXw07^: t *1Gq*:E -$Yz51Hh_آȷ6<?Tu͖?N E>=(PsVFf6bqbcPV1ys|Mr~m\#'b<0Ӝ]O)4T=';2E}BIJגS˕\78kA;}GPSe`{!#ԃm?7J@iY46'+(,4~ |ES!|PyX!tu7#/0;oPX,G9ڒ  qR1q]lZ$j_z "XoOe=H#o >^<#(D(>l]d YO 䮚^i5_n`CŠ@F2e Yd{WRM RBY}䌩~a3+kܝ6h[A>*0kQi 3EjAI#RHa٩g!D2iwgk>/R1p蘦+y^"R{ޢlCy7$f:x>62x#fa5A|A-7eD1#"0-'p=:2A0=#*4tyd%D!dk!s6P4vÙg͎<ûgNݧ>`^#X ",=[Pwm+7>劝7T]ЎM} afU8odTڹ>h,ڎgָq8'մK"|:Y@*{X:6ejAtm&?J0auLFr{?Z<0 ܊mb>_hBuyz gS,5fs&9YsNrhLw)5 5rmKI]W؂zǷ.,tُ3j[C)KNZwX^Z ==.mOEad-mC'6BOt@ˏfAm-9 -uL/sZuNr%B(l RUQ?h}{;H5R1GJ)zԝ6u`s0, DĿl#ӗsIݛO1,o .^%1rYL eUS2(Nls76ʔaAu`c:c03dXОk56F ?=  41\-4} LdTi蔩I>k_V6 _Fo,5o0'-BkD H3KJ@/r}tV{d xȅ!D5mĆ>'@O$1Wc0.8h5AHSx++pƃw |' CyXZ"=Dj3ybO[Iup,?@(4B#z-@+!W4n}fK$.rقuԚCݭP,+I1NYZZ:8WTbK~|$%]Ps-D,"Y=D˺%U5顎2ui`y >by`7y( 'Q<#W(!`oBKw $4ܓ:۱[20 o{bAx`raͻ'qP2*pgwiK&c)ȁ pb {ׯ=FG9s0Uu1 D<ؗ|kߜN O/𶿸j[!حxĠES"p)C'E?Ne|ht|(QǕ_NM'AD18$Qx>BYÞK KfAl$j8o4߫E'Dm{kI=he2;˳ iYFLFlm w`?i DqtG]>- Ց `NDZ^FAJᓱU's[li4SH|cX4HA,FlzsQֹ[ut%1AB5B5Aw F­)l.ΫgGٛqhhѩQ[9 gw̵pQAmr }@_cYy!U}Ay)ӺѿYƊ:`Pc?A;hx7Լf(2y0Wɨ=妬 Nh3gKƟ#TT?ϵ? w'y٢grg'6lIUjSԓ9م7/iP53$g/Q (nF55\Ep -C½\^C $|fd@d ::ۆ^gU:TAƗBGnBSz :[ WbLuwdq}`x]tf2˒yz!5mlz"nID>F*I뒆>_6?lL{1TeySn6ɛ5 x/%DhW`_n)dFDnyB؛Ԃ98˔p/Ex E護 qtJ aM`*'.xql=97yWW"֪7+nd!"S??PQ`'@d2?4L&/l3aϗXtj^_ 4 n/}TyC tE]Q߻)34sxWyӐbcɽ*[y~^`wl"IPQ# ԹӅD lіn_UbYi|9˜ĝB4/[_BҰ%+vx,Ge ]*Df3f~}xo|#[1'K)(vrȤo`WVYG|hʛr(m&Foz}h .^-%+{;i9Q]{ia>Me7At;,2)((TH,`3r Ϛpr\@6u[rU̽(k$ix#}#{9IpH aC - 3aG$ߴT悛gєRH!BIo7Gz*X!_`d˺U%j*}u'H)Q#M^3(Ǥ=vG9qy/asLX45=ΖީkI1jQ2H7RMPlb .vL, 2W:/@ ]5hC,'SG/O+ atSObX?ÉG7g5 )JFh0$!21S^k 6Qm2HīOe+{Ewl.ٽ޵Znjؘ rmpq{\ ~L8& _PuVvoD gT$SM}ӣ8b=1(tͿ3/o2ZF}d| ⃇g`+ LscwM7cLw^Ž&`%7D )QDőg3A-6ufj|!o }]|P )gv.009bն#ُ ?TBN~i27Jazjhy WW)Zc!Bͩcvi[|t k>w=m-F u,v-V׆hUjUK` 3MaH+ݮ\WO1{s]GIi%$^@fu]RDQ %$yT-\o<]ܱfL7ÄSNe 2B3nNJN+9 /Hd&xǮ<]U+ @ 83xɧ}UCmjG|X{6 a‘ԡn)1ذ|0Yfy`Yd,-#heY%ㆀk 檪kFx)ɲK\M\f![xϑ '|fkK2ky|ԾLSȗr0¨Zr\6ǎgu.^*pp۴fvi4%iu?/k,'Y."Y/ϭ~u].s[ gt !,mz#hDtYniP %q'Mק0G9Ψǧh`7ب 7,#lV'12GT[$|Ŕma !hm߾h )̢\|d^bTahBնIzMoc^C!Ins9ǠE״Z^4W:I=NB\@fDlJ:e|$8l]j +l>0[ xr6H~}MFde:nk9wV87Wm}Y>݉H7c;r&$/LkuS}H.ibۼ.$ `9zc9"ӁV8i)ϕҰ`?q3%͸Qy7Z^z3/\n,^@R,1e &Bu$ffo0[,\{~gtS`ko-dUaeU~TBj[ٶ{>Π]>ftLK׸ EP\2X4®0Tol;]fY8;*='B?S/D֢WS 4̄2IYg$όɒ mipJKkSsm x3&=W;p,8!s.3r,*^Bq,l`TdD0\TQ:(TOͬP 9T2‡UіD{jYlDC[U4LM`, #v`, @)$wf'yNz:"'eI9b^XmM(+ ţ٭+WZL2!lbMmb/+N z}ˡcpC>_SgV&T̘w\ Jet qן+o $zCSߘDf@?~(?ígNmooɥ9syjT(f@w7WNZ0=m= 5KYҦvDu)PvX=~/ A&4c-kO]?qϹ"[bڢZF9ŧ𧨅!S7 ȆB?)=xYz2c-RhjE C!3iabV2_S{h@BzVrqQ ë2$ YxV0A^Sیpyw#gX^5,x[1ZPE}JreKZO>~PxVA4sQRWDsűq7pبڬ<- qVo8q| XÍ7j~`cy41BTBX/3}.e[6˝厖J_8\ S|󶷇 9 gv2饜#O1Xَ;e]fK$눔=G@ (nQP8Tb|#LFGE.G=3/qWIy꾤D:B/cVqleܼVՒOpDySܥ%ݓq96qŖ= ~hMfә'lJ0dFa/)^xQAf.Jd*Ϧݰ uD i 2YoJdJFV ꒗eh@DKifaS oNy>"x?}8BN1ǰo]V= 6DDcZ,*ձU lH-=#dEhK|1Vh"򒓚n:/᫪ ?Ea8qI6Xc2AB/Cj:ہFт ܊,h=0͟SE؝'3v1mɉGJfVVAMy\ .pp kȳN5Uw %E$>wN"p.p8qlrU vuFC!*|n~5L]|65 cs5ILXbDXR"TXϹFw*. 0be&uVj q;U5h/e/*L~3'8>ވkMa~ K' 5d|T|n`UDԔ^ɘ_ǞOPLeLAvs^^xw+"is"D06ZT90 HtRI} G$!{4-䱫V6fȀ5$օ&.\5*SONL0XK8?/` nrk5s4,_T%1>gswUgvE.<|)tcEEg3o #?I|b3 ȂtїKբ+frI4S:_P6"BH|4.)`p$\zOWzivvRґ8#䋲oދX~cHj+\: -{wi~' 6UZ@x|ۈ(@Z!?p0wԼBhIӨʅ!ŮyL]}68I_ߌK+{=R:ƴ7n)ۃ77Pڔ9_<<9(Fw/~2n*E6Ҡ1Ky}GCSMS QqzOw!c+4>bU/^7Ï{ H9A:$󇧭l@Cw85ǏAY>T 4g%Qi)r[iD "4z¤[c+4 jaB 9mۻCAW0~ÖyZvR25 r]# F>S7qK/w߮E^07$ yƉmom{C-̿}ѐD? pJBFf7_ s(@ꟖA+5X ?e0OKpϵ÷M\Gtp}Z0ȍcji>3 r-;-2/EWh5iԴ=X_S!_ VsU\E24sjn<:M/ )7ᾘБIIx+qMPQ s0cF}4w=";:?- y *c!pew=YוuYFm0о ߮k()uo M~%mZP(uM#ml«[3×$aZMvL4*RxB0p+kpºV.?Nm9 M<4ZYwtLrlFE{X"xγ%B{ʊi==`w,2wnu@کy $9=o)+$E6h34I_fL^#[A|(}!$:90{"XQFos[;+aZ<tΝJf Og/Y16kUPY4h0AVvBDA߸T8 c& :kiaAUxk 4bxZ fi#ΘW<ȺVY3DVpiW%Sթɴ[j(Q'jEcu)'@XMFڳ@Z{g:,#4FF&/cN`@%F"2j^K&ظWUM\d*a"k6Z3f@xCm=6) `]~SO%aMmPp&7g"W+4F'\4Qte;9M1Ѱ*4݄H4_Bވ&mܜ2ƌCh#'6 #eՂFF.ۧ}\ْ9˴Ab~L4ZG[ ̌ ly/ ҶU|b6+z}ҶPi>H7f9F5LkMkR,N1>j_eA0`ȻNGD1r_o'$? Vrz(T+o*y(|P:*ټ4QtJpcK[-'klڥBj҅q"f\K;`q(*M@a*U|%h 22xƙQ#> #:~h1HfQ*`B9fA{f̓ˀXX+Z[,T ̄uP9e4f6BTSU_?Zq5~WI`Sa ˋکղCRqI`6y>9&I4Qn<4›",6:ɂo5  eƗ<$2[(u|ʦALNRE v^Y]XcB+^{Pb=6{uv'oUTy lQd6 @gZ΀Sɾ !L;>ѧ=IχɁ~zɕ&mXAi q5FMu U6BEu[zޏ8M;dO>ۭ3e7>hCDħɎ7PjP3+^_|4p"cXti2!5_tamІ*`>ZᙄTk{Kfd,a \f3HlJY!5xP]ڤEN[~t 11*IZEsU0(9,(D٨#aO*E>Y2x'RgW=iܑFwi>',E`UF/Ii MꪬsET+Ar,uU, '7sաz3w"C?jL>[-D,u/*±cgn9|L}dM2DrkLbBg?88"آQz*GUFG?=7OO:8>d!K!w3O ׭ _PUP(lmݪ%ܮpm(=U*;IFC",׫jzC@&ت 1N!ȱn6e/?ޢ^x9;UsK',|`had1#lÆq=ԇCŠ&.ibO,Ӻ-r=ͩ3jJ-J P:}"L3E l?:ꏳk_AXCT'L oNRs ~8E$E3̭n+ Vz41軗ƈ=Mdždn95+s_+OO+LpSozo0fLEUNhChnm̥jj*Bd#SϵY;mq d[F&gcD˷-O/{7pHY*iG9H>9y ScnD/W> GA|;L@R0'4bHgt5xP6k{UoW> _/w,N| dkoM쭁{r-z?+mS)W(9xRU UsƠ= ^>.V)Rd 6K8ԴYmGBUnT{9{,EX_,^܈rACMy]@/pŝry87Z.%*)2jk-(b7Ź+KnsHB09]$׫ V4ܹspdtiV޼ ܓX* ⚮%UERX5L:D~fhuŸ vW_Ʌ@tOT5EB%yڙ **֔5E}^GP [^l`F؀0lthh(s)dm&bAUM=19x3*wrѻKc䭞QY0)M鷺AYcI!_2J\wU@7rk7aO^+7QL*URn?I'#}|0MՓ"BN DLnaKzcEɬKcv]|uM] \ RbOZ8] [ ]^;`PexSܢ2*i>FLKtg=yCHBֳDӌ2;DiWWO!Ym1.mDIZ]U3*ANE,@ 2Wu(|a䝕rp›IA q@^Y6m͎v~sY׉~9=~J`of)s*A{a¬ȟˮMSwyVB C"JmuyBFa 5@]@`e6 vzmbc5): x042o 7l3 jf;}W?Qc^!ٸV 0_R*f‚*J] V\(kӪnKrPj,&׈^c8YbzIQr". >9KohXeE:c'!@ǻ̕Z#AL3m"bl]\JcPJqi,"ңHk%S~-zO dICEPwËƢv)V.9۹ R,M$4m*.m,'Wgu$ dLG^BMS+ Mv"fd[Wü'Nqɤ_<b?$8}LAC7C@"e,H{$ܮf[,y ށxyEYPx =Vz7\"L?Yh> rۭ4"}௭uf hNIEV`M}IL{01j`thۄUbM~AL Ŕy&mS6PFA ڸxC+Td@}B3-0cA>KB.~tڕf"kM6Wi͋c8㉂U:O'o 13݄VnMJƵ`45nkdz}@Csݦ:5'?~4=¶u)Щ?;3,yG0"ќ5Tdl^Ƌ8 9.me?jKfH%X3$iM|ۖ>؏Z0 E`&JI}FCJ!`->_Dɰ/5ǬӠ}kXn&)Z 6%Oo܎UǡqVsڣVFJ!/ؖ`2Ewv=G˒rIk}n\#jvJϑ˪2J633f;,km,ΦflsluR-̟&e<^MNWQXN|it%sikS̒%i'ξE!tYl-3Itm=/Z<"c=mOP?)%e&*EI!He_꬚{YɇwKB%+%U6\?t]Bw9AzI(쨈w{ٝ+;^@$8'pu > bZni7 G0O+@P/Z+fjnSAuQX%PNڭa0v}! ?g{9鹬sFPi1nQjK;zmT`=AL=ޗZكIռ6«LlJ} 9isvg%E{kphz3S)*t?sFߛ1VzN_=Q-s&́@6!lp"P +p3oY9fK{ٮAOi灆 Ij*d!EyTo;u!LB3*t`)jz ZJ;':mQ`DC}9̹>:oy&!&OwhE~)6&ۇvh,-ܙA{]H&I[7\,Jw޿(ַ;f֘,! y]׌f,D˃5hhZ@\@3p~'9YKoz N; 8d|ۊ_R8fd^$Dw$2~*BRdt PfCQvIOQj:!ƥ-~?Ϗ4 F`2J-'I4C !sPP;ռ'^UKhA .5D; 55˹ATg菭,J ޶-*cutQ1-uT9WA,Z*4V-ndE1p JhK#_1D~)d82/Ѭn6a~F.x6(@[gI[g` ~=> bI1%)(kmEaUQ,&^Gd?b$-Y]rt9Q! G}LAI @/v[/` 6nM;=PPUi^)t=3T e-3j=Kh!NJ{ۇc06c`Btuqf(R߳LjnrYdd 5Lj:A5CZ:GTHҩ+ bB$P0 Cf&]23#Pg=bM~3\s}?=gpQ$m9 X͵K)ɹbiE5ȒG':Pfih-3M VoҤC/2bwG vD#FwJg`T*a.QA# =6u~NJk"n2 -'*꜡7eDuѩ BXGԍ ;BN; &L}($v8}OPs@f]]Q}63$,jS 8HFZF{3DHGZ$l`>AAt@UM