sssd-ldap-2.5.2-1.el8 >  A `2U]:uDjMl%v# }LJ!a3ŕ"DQ&ag3Շ.V.Mp'؋/! P*M\`"lgSI2Aغcfz;U"Semjg1{ l쌹 Jʡ4@(Wsu|=>25w~>@-g sKǐ0v`z&<\hOSm߂8T&m eF(.ӿ![F,aJЬEHؑxDkd݉_,6iP8'2MZ폀TQBy: X}5/o㽉G*Kg”INHwą9Nz doYE!46(߯27Y[ 6YDi ONw-ӷd[|)7 'A`_ŀJaJRUEW8%b.cƧV8S$eDO2Re4233efe0969acad75f1e04b5bd34dd6cea02ff7c1fb2856ef0cf647f50f358086243f68bce6e227e81f56d8f5b02530045cde29)̉`2U]K$ʍ ("RF=w=@Uڭ Y⏁]&`AUi}GUa=l򞴈,jmZH~A/1[il\:99l%d]0!il 5]4) ε֬db|=E}sAs-W?*y͙"6 ?J^(-XPޯP-4/])! ;#PNW 깫EB<+g1o4#~iʤCDRiL%@60'%Vq4i>>.fwjZ^)ZjFmEIf,\b4nH1zoL &xգ_<%l|t:!~~+~}I5<^X:#2R]Wiw u"{v04pɷɫ!3]<ڂ umL z]' Pշm_94(ٳbd>p?k?kd   6 8>H    ~ 6|.. '.   ( 8 9$:`GcxHcIcXdYd\d,]dd^e] bf4dgegfglgtgugvhwixiyj'jjjkCsssd-ldap2.5.21.el8The LDAP back end of the SSSDProvides the LDAP back end that the SSSD can utilize to fetch identity data from and authenticate against an LDAP server.` x86-02.mbox.centos.org[CentOSCentOSGPLv3+CentOS Buildsys Applications/Systemhttps://github.com/SSSD/sssdlinuxx86_64)oKE\=5A UAAA큤``````````````c583a99cfdf7fe5e5623321b09fe334eb9845fbcd7c53dc26043e0e66af7093c8ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903cf0bdad50097719dc3e109ba433ec88cda4a7cf23c01e749c278b903a597da35d436d160676e1de1907f1c67880d3395983a3d23911082a324fdfa88d2b1887b904a6de0dbf2dcd6f07e6c75edd96c55527acb703cdecff470680e21c74bde7dbac490eda5106bf7b5f97e62d9fcdcf1fe7f09ddfd713d3cf6bb81b9ae4f2528b2d05784e1d85efd103d7677401c98023b4164df2e928085e4461c39c247c4f56f78a71bf7d948d1a6f586263b8e6b0046684020f72753c4af1d912c8fe86c542bc19cb037ea2aa1bef45387198b563e27d60edbe408a37a8526afbbac8d12ab8e5e3bb37601195af4035d2c4dff86bc0ebd2f45c6f1ad2d6ae62b627ed36763../../../../usr/lib64/sssd/libsss_ldap.sorootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-2.5.2-1.el8.src.rpmlibsss_ldap.so()(64bit)sssd-ldapsssd-ldap(x86-64)@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@    @libbasicobjects.so.0()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.4)(64bit)libcollection.so.4()(64bit)libcom_err.so.2()(64bit)libcrypto.so.1.1()(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.5()(64bit)libk5crypto.so.3()(64bit)libkeyutils.so.1()(64bit)libkrb5.so.3()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.2()(64bit)libpcre2-8.so.0()(64bit)libpopt.so.0()(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsss_cert.so()(64bit)libsss_certmaplibsss_certmap.so.0()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_idmaplibsss_idmap.so.0()(64bit)libsss_krb5_common.so()(64bit)libsss_ldap_common.so()(64bit)libsss_util.so()(64bit)libsystemd.so.0()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)libtevent.so.0(TEVENT_0.9.9)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsXz)rtld(GNU_HASH)sssd-commonsssd-krb5-common2.5.2-1.el82.5.2-1.el83.0.4-14.6.0-14.0-15.2-12.5.2-1.el82.5.2-1.el8sssd1.10.0-8.beta24.14.3`.`@`[` @`&m`@`x@__@_@_#___[@_?@_-B@_@_@^@^@^^(@^oj@^ku^Y^S^J@^C^0"@^0"@^0"@^@^@^@]f@]f@] @] @]+]]Y]Y]|@]o@]k]k]Y=]Y=]Y=]Y=]Y=]M`@]M`@]M`@]D%]D%]D%]9]9]]]@]@\\`@\]o@\\\\\\\@\>@\>@\>@\\\\l@[Ѱ@[^[[ā@[ā@[ā@[;@[;@[;@[;@[;@[[@[@[@[@[@[t[#@[#@[@[@[qr[;e@["XZZ&Zw@Z Z$Zz@ZyZiZiZWQZWQZ%8Z@Z@YZ@Y@YYzYKYyYw2YRHYRHY@X-XX~@XO@X}@X@XX6@XWXOXXWW@WWW@WWv[@Wi,@W5W@W@V3VVVvV%@VqR@VO @V<@V/g@V$@V @V @UpU|@U4@UUUU@UzUzUzUL@UL@U.RU@TTT@T~T8TܕT@T@TTTq@T@T@Tp@TA@TuTto@TG@TD@TT @S0SS@S.SP@S @Sg@SrS!@SkqSkqSG@SFSCS!SSRRpRpR^R[RSRNREs@RD!R@R@RNQB@Q@QQQکQQQo@Q)@Q@QQ@Q@QbQbQV@Q'@QQQQnQZ@QU@Q0@QQQ@Q@QQ @QQh@PP@P@P@Pz@Pz@PqnPl(PaPaPS@PH@PDPM>M2@MMzMx@Mj - 2.5.2-1Alexey Tikhonov - 2.5.1-2Alexey Tikhonov - 2.5.1-1Alexey Tikhonov - 2.5.0-1Alexey Tikhonov - 2.4.0-8Alexey Tikhonov - 2.4.0-7Alexey Tikhonov - 2.4.0-6Alexey Tikhonov - 2.4.0-5Alexey Tikhonov - 2.4.0-4Alexey Tikhonov - 2.4.0-3Alexey Tikhonov - 2.4.0-2Alexey Tikhonov - 2.4.0-1Alexey Tikhonov - 2.3.0-9Alexey Tikhonov - 2.3.0-8Alexey Tikhonov - 2.3.0-7Alexey Tikhonov - 2.3.0-6Alexey Tikhonov - 2.3.0-5Alexey Tikhonov - 2.3.0-4Alexey Tikhonov - 2.3.0-3Alexey Tikhonov - 2.3.0-2Alexey Tikhonov - 2.3.0-1Alexey Tikhonov - 2.2.3-19Alexey Tikhonov - 2.2.3-19Michal Židek - 2.2.3-18Alexey Tikhonov - 2.2.3-17Alexey Tikhonov - 2.2.3-16Michal Židek - 2.2.3-15Michal Židek - 2.2.3-14Michal Židek - 2.2.3-13Michal Židek - 2.2.3-12Michal Židek - 2.2.3-11Michal Židek - 2.2.3-10Michal Židek - 2.2.3-9Michal Židek - 2.2.3-8Michal Židek - 2.2.3-7Michal Židek - 2.2.3-6Michal Židek - 2.2.3-5Michal Židek - 2.2.3-4Michal Židek - 2.2.3-3Michal Židek - 2.2.3-2Michal Židek - 2.2.3-1Michal Židek - 2.2.2-1Michal Židek - 2.2.0-19Michal Židek - 2.2.0-18Michal Židek - 2.2.0-17Michal Židek - 2.2.0-16Michal Židek - 2.2.0-15Michal Židek - 2.2.0-14Michal Židek - 2.2.0-13Michal Židek - 2.2.0-12Michal Židek - 2.2.0-11Michal Židek - 2.2.0-10Michal Židek - 2.2.0-9Michal Židek - 2.2.0-8Michal Židek - 2.2.0-7Michal Židek - 2.2.0-6Jakub Hrozek - 2.2.0-5Jakub Hrozek - 2.2.0-4Jakub Hrozek - 2.2.0-3Jakub Hrozek - 2.2.0-2Michal Židek - 2.2.0-1Michal Židek - 2.1.0-1Michal Židek - 2.0.0-45Jakub Hrozek - 2.0.0-43Michal Židek - 2.0.0-42Michal Židek - 2.0.0-41Michal Židek - 2.0.0-40Michal Židek - 2.0.0-39Michal Židek - 2.0.0-38Michal Židek - 2.0.0-36Michal Židek - 2.0.0-35Michal Židek - 2.0.0-34Michal Židek - 2.0.0-33Michal Židek - 2.0.0-32Michal Židek - 2.0.0-31Michal Židek - 2.0.0-30Michal Židek - 2.0.0-29Michal Židek - 2.0.0-28Michal Židek - 2.0.0-27Michal Židek - 2.0.0-26Michal Židek - 2.0.0-25Michal Židek - 2.0.0-24Jakub Hrozek - 2.0.0-23Jakub Hrozek - 2.0.0-22Jakub Hrozek - 2.0.0-21Jakub Hrozek - 2.0.0-20Jakub Hrozek - 2.0.0-19Jakub Hrozek - 2.0.0-18Jakub Hrozek - 2.0.0-17Jakub Hrozek - 2.0.0-16Jakub Hrozek - 2.0.0-15Jakub Hrozek - 2.0.0-14Jakub Hrozek - 2.0.0-13Jakub Hrozek - 2.0.0-12Jakub Hrozek - 2.0.0-11Jakub Hrozek - 2.0.0-10Jakub Hrozek - 2.0.0-9Jakub Hrozek - 2.0.0-8Jakub Hrozek - 2.0.0-7Jakub Hrozek - 2.0.0-6Jakub Hrozek - 2.0.0-5Jakub Hrozek - 2.0.0-4Jakub Hrozek - 2.0.0-3Jakub Hrozek - 2.0.0-2Fabiano Fidêncio - 2.0.0-1Tomas Orsava - 1.16.2-2Fabiano Fidêncio - 1.16.2-1Fabiano Fidêncio - 1.16.1-3Fabiano Fidêncio - 1.16.1-2Fabiano Fidêncio - 1.16.1-1Lukas Slebodnik - 1.16.0-13Fabiano Fidêncio - 1.16.0-12Lukas Slebodnik - 1.16.0-11Lukas Slebodnik - 1.16.0-10Igor Gnatenko - 1.16.0-9Lukas Slebodnik - 1.16.0-8Lukas Slebodnik - 1.16.0-7Björn Esser - 1.16.0-6Lukas Slebodnik - 1.16.0-5Lukas Slebodnik - 1.16.0-4Jakub Hrozek - 1.16.0-3Lukas Slebodnik - 1.16.0-2Lukas Slebodnik - 1.16.0-1Lukas Slebodnik - 1.15.3-5Lukas Slebodnik - 1.15.3-4Lukas Slebodnik - 1.15.3-3Fedora Release Engineering - 1.15.3-2Lukas Slebodnik - 1.15.3-1Lukas Slebodnik - 1.15.3-0.beta.5Lukas Slebodnik - 1.15.3-0.beta.4Lukas Slebodnik - 1.15.3-0.beta.3Lukas Slebodnik - 1.15.3-0.beta.2Lukas Slebodnik - 1.15.3-0.beta.1Lukas Slebodnik - 1.15.2-1Lukas Slebodnik - 1.15.1-1Jakub Hrozek - 1.15.0-4Lukas Slebodnik - 1.15.0-3Fedora Release Engineering - 1.15.0-2Lukas Slebodnik - 1.15.0-1Miro Hrončok - 1.14.2-3Lukas Slebodnik - 1.14.2-2Lukas Slebodnik - 1.14.2-1Lukas Slebodnik - 1.14.1-4Lukas Slebodnik - 1.14.1-3Lukas Slebodnik - 1.14.1-2Lukas Slebodnik - 1.14.1-1Stephen Gallagher - 1.14.0-5Fedora Release Engineering - 1.14.0-4Lukas Slebodnik - 1.14.0-3Lukas Slebodnik - 1.14.0-2.betaLukas Slebodnik - 1.14.0-1.alphaLukas Slebodnik - 1.13.4-3Lukas Slebodnik - 1.13.4-2Lukas Slebodnik - 1.13.4-1Lukas Slebodnik - 1.13.3-6Lukas Slebodnik - 1.13.3-5Fedora Release Engineering - 1.13.3-4Lukas Slebodnik - 1.13.3-3Lukas Slebodnik - 1.13.3-2Lukas Slebodnik - 1.13.3-1Lukas Slebodnik - 1.13.2-1Robert Kuska - 1.13.1-5Lukas Slebodnik - 1.13.1-4Lukas Slebodnik - 1.13.1-3Lukas Slebodnik - 1.13.1-2Lukas Slebodnik - 1.13.1-1Lukas Slebodnik - 1.13.0-6Lukas Slebodnik - 1.13.0-5Lukas Slebodnik - 1.13.0-4Lukas Slebodnik - 1.13.0-3Lukas Slebodnik - 1.13.0-2.alphaLukas Slebodnik - 1.13.0-1.alphaFedora Release Engineering - 1.12.5-4Lukas Slebodnik - 1.12.5-3Lukas Slebodnik - 1.12.5-2Lukas Slebodnik - 1.12.5-1Lukas Slebodnik - 1.12.4-8Lukas Slebodnik - 1.12.4-7Lukas Slebodnik - 1.12.4-6Lukas Slebodnik - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Lukas Slebodnik - 1.12.4-2Lukas Slebodnik - 1.12.4-1Lukas Slebodnik - 1.12.3-7Lukas Slebodnik - 1.12.3-6Jakub Hrozek - 1.12.3-5Lukas Slebodnik - 1.12.3-4Lukas Slebodnik - 1.12.3-3Lukas Slebodnik - 1.12.3-2Lukas Slebodnik - 1.12.3-1Lukas Slebodnik - 1.12.2-8Sumit Bose - 1.12.2-7Lukas Slebodnik - 1.12.2-6Jakub Hrozek - 1.12.2-5Jakub Hrozek - 1.12.2-4Jakub Hrozek - 1.12.2-3Jakub Hrozek - 1.12.2-2Jakub Hrozek - 1.12.2-1Jakub Hrozek - 1.12.1-2Jakub Hrozek - 1.12.1-1Jakub Hrozek - 1.12.0-7Fedora Release Engineering - 1.12.0-6Stephen Gallagher 1.12.0-5Jakub Hrozek - 1.12.0-1Fedora Release Engineering - 1.12.0-4.beta2Jakub Hrozek - 1.12.0-1.beta2Jakub Hrozek - 1.12.0-2.beta1Jakub Hrozek - 1.12.0-1.beta1Jakub Hrozek - 1.11.5.1-4Stephen Gallagher - 1.11.5.1-3Stephen Gallagher - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Stephen Gallagher 1.11.5-2Jakub Hrozek - 1.11.5-1Sumit Bose - 1.11.4-3Jakub Hrozek - 1.11.4-2Jakub Hrozek - 1.11.4-1Jakub Hrozek - 1.11.3-2Jakub Hrozek - 1.11.3-1Jakub Hrozek - 1.11.2-1Sumit Bose - 1.11.1-5Sumit Bose - 1.11.1-4Jakub Hrozek - 1.11.1-3Jakub Hrozek - 1.11.1-2Jakub Hrozek - 1.11.1-1Jakub Hrozek - 1.11.0-3Jakub Hrozek - 1.11.0-2Jakub Hrozek - 1.11.0-1Jakub Hrozek - 1.11.0-0.4.beta2Fedora Release Engineering - 1.11.0-0.3.beta2Jakub Hrozek - 1.11.0.2beta2Jakub Hrozek - 1.11.0.1beta2Jakub Hrozek - 1.10.1-1Jakub Hrozek - 1.10.0-17Stephen Gallagher - 1.10.0-16Stephen Gallagher - 1.10.0-15Stephen Gallagher - 1.10.0-14Jakub Hrozek - 1.10.0-13Dan Horák - 1.10.0-12.beta2Jakub Hrozek - 1.10.0-11.beta2Jakub Hrozek - 1.10.0-10.beta2Jakub Hrozek - 1.10.0-9.beta2Jakub Hrozek - 1.10.0-8.beta1Jakub Hrozek - 1.10.0-8.beta2Jakub Hrozek - 1.10.0-7.beta1Jakub Hrozek - 1.10.0-6.beta1Jakub Hrozek - 1.10.0-5.beta1Jakub Hrozek - 1.10.0-4.beta1Jakub Hrozek - 1.10.0-3.beta1Jakub Hrozek - 1.10.0-2.alpha1Jakub Hrozek - 1.10.0-1.alpha1Jakub Hrozek - 1.9.5-10Stephen Gallagher - 1.9.4-9Jakub Hrozek - 1.9.4-8Jakub Hrozek - 1.9.4-7Jakub Hrozek - 1.9.4-6Jakub Hrozek - 1.9.4-5Jakub Hrozek - 1.9.4-4Jakub Hrozek - 1.9.4-3Jakub Hrozek - 1.9.4-2Jakub Hrozek - 1.9.4-1Jakub Hrozek - 1.9.3-1Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-24Jakub Hrozek - 1.9.0-23Jakub Hrozek - 1.9.0-22.rc1Jakub Hrozek - 1.9.0-21.beta7Jakub Hrozek - 1.9.0-20.beta6Jakub Hrozek - 1.9.0-19.beta6Jakub Hrozek - 1.9.0-18.beta6Jakub Hrozek - 1.9.0-17.beta6Jakub Hrozek - 1.9.0-16.beta6Jakub Hrozek - 1.9.0-14.beta6Jakub Hrozek - 1.9.0-13.beta6Fedora Release Engineering - 1.9.0-13.beta5Jakub Hrozek - 1.9.0-12.beta5Stephen Gallagher - 1.9.0-11.beta4Jakub Hrozek - 1.9.0-10.beta4Jakub Hrozek - 1.9.0-9.beta4Stephen Gallagher - 1.9.0-8.beta3Stephen Gallagher - 1.9.0-7.beta2Stephen Gallagher - 1.9.0-6.beta2Stephen Gallagher - 1.9.0-5.beta2Stephen Gallagher - 1.9.0-4.beta1Stephen Gallagher - 1.9.0-3.beta1Stephen Gallagher - 1.9.0-2.beta1Stephen Gallagher - 1.9.0-1.beta1Stephen Gallagher - 1.8.3-11Stephen Gallagher - 1.8.2-10Stephen Gallagher - 1.8.1-9Stephen Gallagher - 1.8.1-8Stephen Gallagher - 1.8.1-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5.beta3Stephen Gallagher - 1.8.0-4.beta3Petr Pisar - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-1.beta2Stephen Gallagher - 1.8.0-1.beta1Stephen Gallagher - 1.7.0-5Stephen Gallagher - 1.7.0-4Stephen Gallagher - 1.7.0-3Fedora Release Engineering - 1.7.0-2Stephen Gallagher - 1.7.0-1Stephen Gallagher - 1.6.4-1Stephen Gallagher - 1.6.3-5Stephen Gallagher - 1.6.3-4Jakub Hrozek - 1.6.3-3Stephen Gallagher - 1.6.3-2Stephen Gallagher - 1.6.3-1Fedora Release Engineering - 1.6.2-5Stephen Gallagher - 1.6.2-4Stephen Gallagher - 1.6.2-3Stephen Gallagher - 1.6.2-2Stephen Gallagher - 1.6.2-1Stephen Gallagher - 1.6.1-1Stephen Gallagher - 1.6.0-2Stephen Gallagher - 1.6.0-1Stephen Gallagher - 1.5.11-2Stephen Gallagher - 1.5.10-1Stephen Gallagher - 1.5.9-1Stephen Gallagher - 1.5.8-1Stephen Gallagher - 1.5.7-3Stephen Gallagher - 1.5.7-2Stephen Gallagher - 1.5.7-1Stephen Gallagher - 1.5.6.1-1Stephen Gallagher - 1.5.6-1Stephen Gallagher - 1.5.5-5Stephen Gallagher - 1.5.5-4Stephen Gallagher - 1.5.5-3Stephen Gallagher - 1.5.5-2Stephen Gallagher - 1.5.5-1Stephen Gallagher - 1.5.4-1Stephen Gallagher - 1.5.3-2Stephen Gallagher - 1.5.3-1Stephen Gallagher - 1.5.2-1Simo Sorce - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Fedora Release Engineering - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.4.1-3Stephen Gallagher - 1.4.1-2Stephen Gallagher - 1.4.1-1Stephen Gallagher - 1.4.0-2Stephen Gallagher - 1.4.0-1Stephen Gallagher - 1.3.0-35Stephen Gallagher - 1.3.0-34Stephen Gallagher - 1.3.0-33Stephen Gallagher - 1.3.0-32Stephen Gallagher - 1.3.0-31Stephen Gallagher - 1.3.0-30David Malcolm - 1.2.91-21Stephen Gallagher - 1.2.91-20Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1693379 - sssd_be and sss_cache too heavy on CPU - Resolves: rhbz#1909373 - Missing search index for `originalADgidNumber` - Resolves: rhbz#1954630 - [RFE] Improve debug messages by adding a unique tag for each request the backend is handling - Resolves: rhbz#1936891 - SSSD Error Msg Improvement: Bad address - Resolves: rhbz#1364596 - sssd still showing ipa user after removed from last group - Resolves: rhbz#1979404 - Changes made to /etc/pam.d/sssd-shadowutils are overwritten back to default on sssd-common package upgrade- Resolves: rhbz#1974257 - 'debug_microseconds' config option is broken - Resolves: rhbz#1936902 - SSSD Error Msg Improvement: Invalid argument - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm (additional patches and rebuild)- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1917444 - SSSD Error Msg Improvement: Server resolution failed: [2]: No such file or directory - Resolves: rhbz#1917511 - SSSD Error Msg Improvement: Failed to resolve server 'server.example.com': Error reading file - Resolves: rhbz#1917535 - sssd.conf man page: parameter dns_resolver_server_timeout and dns_resolver_op_timeout - Resolves: rhbz#1940509 - [RFE] Health and Support Analyzer: Link frontend to backend requests - Resolves: rhbz#1649464 - auto_private_groups not working as expected with posix ipa/ad trust - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1961215 - Invalid sssd-kcm return code if requested operation is not found - Resolves: rhbz#1837090 - SSSD fails nss_getby_name for IPA user with SID if the user has user private group - Resolves: rhbz#1879869 - sudo commands incorrectly exports the KRB5CCNAME environment variable - Resolves: rhbz#1962550 - sss_pac_make_request fails on systems joined to Active Directory. - Resolves: rhbz#1737489 - [RFE] SSSD should honor default Kerberos settings (keytab name) in /etc/krb5.conf- Resolves: rhbz#1947671 - Rebase SSSD for RHEL 8.5 - Resolves: rhbz#1930535 - [abrt] [faf] sssd: monitor_service_shutdown(): /usr/sbin/sssd killed by 11 - Resolves: rhbz#1942387 - Wrong default debug level of sssd tools - Resolves: rhbz#1945888 - Inconsistant debug level for connection logging - Resolves: rhbz#1948657 - pam_sss_gss.so doesn't work with large kerberos tickets - Resolves: rhbz#1949149 - [RFE] Poor man's backtrace - Resolves: rhbz#1920500 - Authentication handshake (ldap_install_tls()) fails due to underlying openssl operation failing with EINTR - Resolves: rhbz#1923964 - [RFE] SSSD Error Msg Improvement: write_krb5info_file failed, authentication might fail. - Resolves: rhbz#1928648 - SSSD logs improvements: clarify which config option applies to each timeout in the logs - Resolves: rhbz#1632159 - sssd-kcm starts successfully for non existent socket_path - Resolves: rhbz#1627112 - RFE: Kerberos ticket renewal for sssd-kcm - Resolves: rhbz#1925505 - [RFE] improve the sssd refresh timers for SUDO queries - Resolves: rhbz#1925514 - [RFE] Randomize the SUDO timeouts upon reconnection - Resolves: rhbz#1925561 - sssd-ldap(5) does not report how to disable the SUDO smart queries - Resolves: rhbz#1925621 - document impact of indices and of scope on performance of LDAP queries - Resolves: rhbz#1855320 - [RFE] RHEL8 sssd: inheritance of the case_sensitive parameter for subdomains. - Resolves: rhbz#1925608 - [RFE] make 'random_offset' addon to 'offline_timeout' option configurable - Resolves: rhbz#1447945 - man page / docs update required: if two certificate matching rules with the same priority match only one is used - Resolves: rhbz#1703436 - sssd not thread-safe in innetgr() - Resolves: rhbz#1713143 - SSSD does not translate the 2FA text labels("first factor" / "second factor") on GDM login and screensaver unlock screen - Resolves: rhbz#1888977 - sss_override: Usage limitations clarification in man page - Resolves: rhbz#1890177 - Clarify "single_prompt" option in "PROMPTING CONFIGURATION SECTION" section of sssd.conf man page - Resolves: rhbz#1902280 - fix sss_cache to also reset cached timestamp - Resolves: rhbz#1935683 - SSSD not detecting subdomain from AD forest (RHEL 8.3) - Resolves: rhbz#1937919 - IPA missing secondary IPA Posix groups in latest sssd 1.16.5-10.el7_9.7 - Resolves: rhbz#1944665 - No gpo found and ad_gpo_implicit_deny set to True still permits user login - Resolves: rhbz#1919942 - sss_override does not take precedence over override_homedir directive- Resolves: rhbz#1926622 - Add support to verify authentication indicators in pam_sss_gss - Resolves: rhbz#1926454 - First smart refresh query contains modifyTimestamp even if the modifyTimestamp is 0. - Resolves: rhbz#1893159 - Default debug level should report all errors / failures (additional patch)- Resolves: rhbz#1920001 - Do not add '%' to group names already prefixed with '%' in IPA sudo rules - Resolves: rhbz#1918433 - sssd unable to lookup certmap rules - Resolves: rhbz#1917382 - [abrt] [faf] sssd: dp_client_handshake_timeout(): /usr/libexec/sssd/sssd_be killed by 11- Resolves: rhbz#1113639 - autofs: return a connection failure until maps have been fetched - Resolves: rhbz#1915395 - Memory leak in the simple access provider - Resolves: rhbz#1915319 - SSSD: SBUS: failures during servers startup - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication (additional patches)- Resolves: rhbz#1631410 - Can't login with smartcard with multiple certs having same ID value - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff (additional patches) - Resolves: rhbz#1893159 - Default debug level should report all errors / failures - Resolves: rhbz#1893698 - [RFE] sudo kerberos authentication- Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1876658 - filter_groups option partially filters the group from 'id' output of the user because gidNumber still appears in 'id' output [RHEL 8] - Resolves: rhbz#1895001 - User lookups over the InfoPipe responder fail intermittently- Resolves: rhbz#1900733 - sssd_be segfaults at be_refresh_get_values_ex() due to NULL ptrs in results of sysdb_search_with_ts_attr() - Resolves: rhbz#1876514 - High CPU utilization by the sssd_kcm process - Resolves: rhbz#1894540 - sssd component logging is now too generic in syslog/journal - Resolves: rhbz#1828483 - filtered ID is appearing due to strange negative cache behavior- This is to bump version to allow rebuild against rebased libldb.- Resolves: rhbz#1881992 - Rebase SSSD for RHEL 8.4 - Resolves: rhbz#1722842 - sssd-kcm does not store TGT with ssh login using GSSAPI - Resolves: rhbz#1734040 - sssd crash in ad_get_account_domain_search() - Resolves: rhbz#1784459 - [RFE] tlog does not allow to exclude some users from session recording - Resolves: rhbz#1791300 - sporadic sssd_be crash on s390x - Resolves: rhbz#1817122 - 'getent group ldapgroupname' doesn't show any LDAP users or some LDAP users when 'rfc2307bis' schema is used with SSSD. - Resolves: rhbz#1819012 - [RFE] Improve AD site discovery process - Resolves: rhbz#1846778 - [RfE] `/usr/libexec/sssd/p11_child` cmdline argument '--nssdb' might be confusing when SSSD was built against OpenSSL - Resolves: rhbz#1873715 - automount sssd issue when 2 automount maps have the same key (one un uppercase, one in lowercase) - Resolves: rhbz#1879860 - correction in sssd.conf:pam_response_filter man page - Resolves: rhbz#1881336 - [RFE] sssd-ldap man page modification for parameter "ldap_referrals" - Resolves: rhbz#1883488 - [RfE] Implement a new sssd.conf option to disable the filter for AD domain local groups from trusted domains - Resolves: rhbz#1884196 - [RFE] Add "enabled" option to domain section in config file - Resolves: rhbz#1884205 - KCM: Increase client idle timeout to 5 minutes - Resolves: rhbz#1884207 - [RFE] ldap: add new option ldap_library_debug_level - Resolves: rhbz#1884213 - [RFE] add offline_timeout_max config option to control offline interval backoff - Resolves: rhbz#1884281 - Secondary LDAP group go missing from 'id' command - Resolves: rhbz#1884301 - [RFE] dyndns: suport asymmetric auth for nsupdate- Resolves: rhbz#1855323 - When ad_gpo_implicit_deny is True, it is permitting users to login when no gpo is applied- Resolves: rhbz#1868387 - system not enforcing GPO rule restriction. ad_gpo_implicit_deny = True is not working - Resolves: rhbz#1854951 - sss-certmap man page change to add clarification for userPrincipalName attribute from AD schema - Resolves: rhbz#1856861 - False errors/warnings are logged in sssd.log file after enabling 2FA prompting settings in sssd.conf - Resolves: rhbz#1869683 - p11_child: default value of ocsp_dgst == sha256 doesn't conform RFC5019 and has to be changed to sha1- Resolves: rhbz#1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command. - Resolves: rhbz#1780404 - smartcards: special characters must be escaped when building search filter- Resolves: rhbz#1820574 - [sssd] RHEL 8.3 Tier 0 Localization- Resolves: rhbz#1821719 - sssd (sssd_be) is consuming 100% CPU, partially due to failing mem-cache - Fixed "requires/provides" rpmdiff warning- Resolves: rhbz#1815584 - id_provider = proxy proxy_lib_name = files returns * in password field, breaking PAM authentication - Resolves: rhbz#1794607 - SSSD must be able to resolve membership involving root with files provider - Resolves: rhbz#1803134 - Improve "unlock" time when user session already active- Resolves: rhbz#1829470 - `sssd.api.conf` and `sssd.api.d` should belong to `python-sssdconfig` package - Resolves: rhbz#1544457 - sssd fails to release file descriptor on child logs after receiving HUP - Resolves: rhbz#1824323 - SSSD user filtering is failing on RHEL 8 after "files" provider rebuilds cache - Resolves: rhbz#1827432 - When the passwd or group files are replaced, sssd stops monitoring the file for inotify events, and no updates are triggered - Resolves: rhbz#1835710 - Change the message "Please enter smart card" to "Please insert smart card" on GDM login with smart-card - Resolves: rhbz#1838037 - Oddjob-mkhomedir fails when using NSS compat - Resolves: rhbz#1845904 - gdm smart card authentication does not work shortly after disconnecting from network. - Resolves: rhbz#1845975 - sssd doesn't follow the link order of AD Group Policy Management - Resolves: rhbz#1845980 - sssd is failing to discover other subdomains in the forest if LDAP entries do not contain AD forest root information - Resolves: rhbz#1845987 - Document how to prevent invalid selinux context for default home directories in SSSD-AD direct integration. - Resolves: rhbz#1845994 - GDM failure loop when no user mapped for smart card - Resolves: rhbz#1846003 - GDM password prompt when cert mapped to multiple users and promptusername is False - Resolves: rhbz#1850961 - /usr/share/systemtap/tapset/sssd_functions.stp missing a comma- Resolves: rhbz#Bug 1723273 - RFE: Add option to specify alternate sssd config file location with "sssctl config-check" command.- Resolves: rhbz#1839037 - Rebase SSSD for RHEL 8.3 - Resolves: rhbz#1843872 - sssd 2.3.0 breaks AD auth due to GPO parsing failure - Resolves: rhbz#1834156 - sssd or sssd-ad not updating their dependencies on "yum update" which breaks working- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate (additional patch)- Resolves: rhbz#1810634 - id command taking 1+ minute for returning user information- Resolves: rhbz#1580506 - [RFE]: sssd to be able to read smartcard certificate EKU and perform an action based on value when generating SSH key from a certificate- Resolves: rhbz#1718193 - p11_child should have an option to skip C_WaitForSlotEvent if the PKCS#11 module does not implement it properly- Resolves: rhbz#1792331 - sssd_be crashes when krb5_realm and krb5_server is omitted and auth_provider is krb5- Resolves: rhbz#1754996 - [sssd] Tier 0 Localization- Resolves: rhbz#1767514 - sssd requires timed sudoers ldap entries to be specified up to the seconds- Resolves: rhbz#1713368 - Add sssd-dbus package as a dependency of sssd-tools* Resolves: rhbz#1794016 - sssd_be frequent crash* Resolves: rhbz#1762415 - Force LDAPS over 636 with AD Access Provider* Resolves: rhbz#1583592 - [RFE] Add configurable randomness to SSSD ldap connection timeout* Resolves: rhbz#1783190 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/sssd_autofs killed by 6* Resolves: rhbz#1785214 - server/be: SIGTERM handling is incorrect* Resolves: rhbz#1785193 - Watchdog implementation or usage is incorrect* Resolves: rhbz#1704199 - pcscd rejecting sssd ldap_child as unauthorized* Resolves: rhbz#1744500 - [Doc]Provide explanation on escape character for match rules sss-certmap* Resolves: rhbz#1781728 - sssctl config-check command does not give proper error messages with line numbers* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release Increasing version number to pick latest libldb* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release PART2: Fix gating issue.* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release* Resolves: rhbz#1753694 - Rebase sssd to the latest upstream release- Resolves: rhbz#1712875 - Old kerberos credentials active instead of valid new ones (kcm)- Resolves: rhbz#1744134 - New defect found in sssd-2.2.0-16.el8 - Also sync. kcm multihost tests with master- Resolves: rhbz#1676385 - pam_sss with smartcard auth does not create gnome keyring - Also apply a patch to fix gating tests issue- Resolves: rhbz#1736861 - dyndns_update = True is no longer enough to get the IP address of the machine updated in IPA upon sssd.service startup- Resolves: rhbz#1736265 - Smart Card auth of local user: endless loop if wrong PIN was provided- Resolves: rhbz#1736796 - sssd config option "default_domain_suffix" should not cause files domain entries to be qualified, this can break sudo access- Resolves: rhbz#1669407 - MAN: Document that PAM stack contains the systemd-user service in the account phase in RHEL-8- Resolves: rhbz#1448094 - sssd-kcm cannot handle big tickets- Resolves: rhbz#1733372 - permission denied on logs when running sssd as non-root user- Resolves: rhbz#1736483 - Sudo prompt for smart card authentication is missing the trailing colon- Resolves: rhbz#1382750 - Conflicting default timeout values- Resolves: rhbz#1699480 - Include libsss_nss_idmap-devel in the Builder repository - This just required a raise in release number and changelog for the record.- Resolves: rhbz#1711318 - p11_child::sign_data() function implementation is not FIPS140 compliant- Resolves: rhbz#1726945 - negative cache does not use values from 'filter_users' config option for known domains- Resolves: rhbz#1729055 - sssd does not pass correct rules to sudo- Resolves: rhbz#1283798 - sssd failover does not work on connecting to non-responsive ldaps:// server- Resolves: rhbz#1725168 - sssd-proxy crashes resolving groups with no members- Resolves: rhbz#1673443 - sssd man pages: The default value of "ldap_user_home_directory" is not mentioned with AD server configuration- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Resolves: rhbz#1687281 Rebase sssd in RHEL-8.1 to the latest upstream release- Replace ARRAY_SIZE with N_ELEMENTS to reflect samba changes. This is done here in order to unblock gating changes before rebase. - Related: rhbz#1682305- Resolves: rhbz#1672780 - gdm login not prompting for username when smart card maps to multiple users- Resolves: rhbz#1645291 - Perform some basic ccache initialization as part of gen_new to avoid a subsequent switch call failure-Resolves: rhbz#1659498 - Re-setting the trusted AD domain fails due to wrong subdomain service name being used-Resolves: rhbz#1660083 - extraAttributes is org.freedesktop.DBus.Error. UnknownProperty: Unknown property- Resolves: rhbz#1661183 - SSSD 2.0 has drastically lower sbus timeout than 1.x, this can result in time outs- Resolves: rhbz#1578014 - sssd does not work under non-root user - Note: Actually the patches were in the 2.0.0-37, this one just adds this changelog because it was missing.- Resolves: rhbz#1652563 - incorrect example in the man page of idmap_sss suggests using * for backend sss- Resolves: rhbz#1466503 - Snippets are not used when sssd.conf does not exist- Resolves: rhbz#1622008 - Error message when IPA server uninstall calls kdestroy caused by KCM returning a wrong error code during the delete operation- Resolves: rhbz#1646113 - Missing concise documentation about valid options for sssd-files-provider- Resolves: rhbz#1625670 - sssd needs to require a newer version of libtalloc and libtevent to avoid an issue in GPO processing- Resolves: 1658813 - PKINIT with KCM does not work- Resolves: 1657898 - SSSD must be cleared/restarted periodically in order to retrieve AD users through IPA Trust- Resolves: rhbz#1655459 - [abrt] [faf] sssd: raise(): /usr/libexec/sssd/proxy_child killed by 6- Resolves: rhbz#1652719 - [SECURITY] sssd returns '/' for emtpy home directories- Resolves: rhbz#1657979 - SSSD's LDAP authentication provider does not work if ID provider is authenticated with GSSAPI- Resolves: rhbz#1657980 - sssd_nss memory leak- Resolves: rhbz#1645566 - SSSD 2.x does not sanitize domain name properly for D-bus, resulting in a crash- Resolves: rhbz#1646168 - sssctl access-report always prints an error message - Resolves: rhbz#1643053 - Restarting the sssd-kcm service should reload the configuration without having to restart the whole sssd - Resolves: rhbz#1640576 - sssctl reports incorrect information about local user's cache entry expiration time - Resolves: rhbz#1645238 - Unable to su to root when logged in as a local user - Resolves: rhbz#1639411 - sssd support for for smartcards using ECC keys- Resolves: rhbz#1642508 - sssd ifp crash when trying to access ipa webui with smart card- Resolves: rhbz#1642372 - SSSD Python getgrouplist API was removed but required for IPA- Related: rhbz#1638150 - session not recording for local user when groups defined - Also add silence a Coverity warning, which is related to rhbz#1637131- Related: rhbz#1637513 - sssd crashes when refreshing expired sudo rules- Add OSCP checks for p11_child - Related: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Related: rhbz#1638006 - Files: The files provider always enumerates which causes duplicate when running getent passwd- Related: rhbz#1637131 - pam_unix unable to match fully qualified username provided by sssd during smartcard auth using gdm- Related: rhbz#1620123 - [RFE] Add option to specify a Smartcard with a PKCS#11 URI- Related: rhbz#1611011 - Support for "require smartcard for login option"- Related: rhbz#1635595 - Cant login with smartcard with multiple certs- Backport more sbus2 fixes - Related: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1636397 - SSSD not fetching all sudo rules from AD- Resolves: rhbz#1628122 - Printing incorrect information about domain with sssctl utility- Resolves: rhbz#1626001 - SSSD should log to syslog if a domain is not started due to a misconfiguration- Resolves: rhbz#1624785 - Remove references of sss_user/group/add/del commands in man pages since local provider is deprecated- Resolves: rhbz#1628126 - [abrt] [faf] sssd: unknown function(): /usr/libexec/sssd/sssd_be killed by 11 crash func _dbus_list_unlink- Resolves: rhbz#1628503 - sssd only sets the SELinux login context if it differs from the default- Resolves: rhbz#1625842 id_provider= local causes SSSD to abort startup- Resolves: rhbz#1615590 - Do not rely on "python" for el8- Resolves: rhbz#1615417 - [RFE] Add Smart Card authentication for local users- Resolves: rhbz#1623878 - crash related to sbus_router_destructor()- Resolves: rhbz#1622026 - sssd 2.0 regression: Kerberos authentication fails with the KCM ccache- Resolves: rhbz#1615460 - Rebase SSSD to the latest released version- Switch hardcoded python3 shebangs into the %{__python3} macro- Update to 1.16.2 release - Cleanup unused global definitions - Remove python2 references from the spec file - Resolves: rhbz#1585313 - Kerberos with sssd-kcm is not working on s390x- Resolves: upstream#3684 - A group is not updated if its member is removed with the cleanup task, but the group does not change - Resolves: upstream#3558 - sudo: report error when two rules share cn - Tone down shutdown messages for socket activated responders - IPA: Qualify the externalUser sudo attribute - Resolves: upstream#3550 - refresh_expired_interval does not work with netgrous in 1.15 - Resolves: upstream#3402 - Support alternative sources for the files provider - Resolves: upstream#3646 - SSSD's GPO code ignores ad_site option - Resolves: upstream#3679 - Make nss netgroup requests more robust - Resolves: upstream#3634 - sssctl COMMAND --help fails if sssd is not configured - Resolves: upstream#3469 - extend sss-certmap man page regarding priority processing - Improve docs/debug message about GC detection - Resolves: upstream#3715 - ipa 389-ds-base crash in krb5-libs - k5_copy_etypes list out of bound? - Resolves: upstream#2653 - Group renaming issue when "id_provider = ldap" is set. - Document which principal does the AD provider use - Resolves: upstream#3680 - GPO: SSSD fails to process GPOs If a rule is defined, but contains no SIDs - Resolves: upstream#3520 - Files provider supports only BE_FILTER_ENUM - Resolves: rhbz#1540703 - FreeIPA/SSSD implicit_file sssd_nss error: The Data Provider returned an error [org.freedesktop.sssd.Error.DataProvider.Fatal]- Resolves: upstream#3573 - sssd won't show netgroups with blank domain - Resolves: upstream#3660 - confdb_expand_app_domains() always fails - Resolves: upstream#3658 - Application domain is not interpreted correctly - Resolves: upstream#3687 - KCM: Don't pass a non null terminated string to json_loads() - Resolves: upstream#3386 - KCM: Payload buffer is too small - Resolves: upstream#3666 - Fix usage of str.decode() in our tests - A few KCM misc fixes- New upstream release 1.16.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_1.html- Resolves: upstream#3621 - backport bug found by static analyzers- Resolves: rhbz#1538643 - SSSD crashes when retrieving a Desktop Profile with no specific host/hostgroup set - Resolves: upstream#3621 - FleetCommander integration must not require capability DAC_OVERRIDE- Resolves: upstream#3618 - selinux_child segfaults in a docker container- Resolves: rhbz#1431153 - sssd: libsss_proxy.so needs to be linked with -ldl- Fix systemd executions/requirements- Fix building on rawhide. Remove -Wl,-z,defs from LDFLAGS- Fix building of sssd-nfs-idmap with libnfsidmap.so.1- Rebuilt for libnfsidmap.so.1- Resolves: upstream#3523 - ABRT crash - /usr/libexec/sssd/sssd_nss in setnetgrent_result_timeout - Resolves: upstream#3588 - sssd_nss consumes more memory until restarted or machine swaps - Resolves: failure in glibc tests https://sourceware.org/bugzilla/show_bug.cgi?id=22530 - Resolves: upstream#3451 - When sssd is configured with id_provider proxy and auth_provider ldap, login fails if the LDAP server is not allowing anonymous binds - Resolves: upstream#3285 - SSSD needs restart after incorrect clock is corrected with AD - Resolves: upstream#3586 - Give a more detailed debug and system-log message if krb5_init_context() failed - Resolves: rhbz#1431153 - SSSD ships a drop-in configuration snippet in /etc/systemd/system - Backport few upstream features from 1.16.1- Resolves: rhbz#1494002 - sssd_nss crashed in cache_req_search_domains_next- Backport extended NSS API from upstream master branch- Resolves: upstream#3529 - sssd-kcm Fix restart during/after upgrade- New upstream release 1.16.0 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_16_0.html- Resolves: rhbz#1499354 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database access on the sock_file system_bus_socket- Resolves: rhbz#1488327 - SELinux is preventing selinux_child from write access on the sock_file system_bus_socket - Resolves: rhbz#1490402 - SSSD does not create /var/lib/sss/deskprofile and fails to download desktop profile data - Resolves: upstream#3485 - getsidbyid does not work with 1.15.3 - Resolves: upstream#3488 - SUDO doesn't work for IPA users on IPA clients after applying ID Views for them in IPA server - Resolves: upstream#3501 - Accessing IdM kerberos ticket fails while id mapping is applied- Backport few upstream patches/fixes- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild- New upstream release 1.15.3 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_3.html- Rebuild with libldb-1.2.0- Fix build issues: Update expided certificate in unit tests- Resolves: rhbz#1445680 - Properly fall back to local Smartcard authentication - Resolves: rhbz#1437199 - sssd-nfs-idmap-1.15.2-1.fc25.x86_64 conflicts with file from package sssd-common-1.15.1-1.fc25.x86_64 - Resolves: rhbz#1063278 - sss_ssh_knownhostsproxy doesn't fall back to ipv4- Fix issue with IPA + SELinux in containers - Resolves: upstream https://fedorahosted.org/sssd/ticket/3297- Backport upstream patches for 1.15.3 pre-release - required for building freeipa-4.5.x in rawhide- New upstream release 1.15.2 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_2.html- New upstream release 1.15.1 - https://docs.pagure.org/SSSD.sssd/users/relnotes/notes_1_15_1.html- Cherry-pick patches from upstream that enable the files provider - Enable the files domain - Retire patch 0501-Partially-revert-CONFIG-Use-default-config-when-none.patch which is superseded by the files domain autoconfiguration - Related: rhbz#1357418 - SSSD fast cache for local users- Add missing %license macro- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild- New upstream release 1.15.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.15.0- Rebuild for Python 3.6- Resolves: rhbz#1369130 - nss_sss should not link against libpthread - Resolves: rhbz#1392916 - sssd failes to start after update - Resolves: rhbz#1398789 - SELinux is preventing sssd from 'write' accesses on the directory /etc/sssd- New upstream release 1.14.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.2- libwbclient-sssd: update interface to version 0.13- Fix regression with krb5_map_user - Resolves: rhbz#1375552 - krb5_map_user doesn't seem effective anymore - Resolves: rhbz#1349286 - authconfig fails with SSSDConfig.NoDomainError: default if nonexistent domain is mentioned- Backport important patches from upstream 1.14.2 prerelease - Resolves: upstream #3154 - sssd exits if clock is adjusted backwards after boot - Resolves: upstream #3163 - resolving IPA nested user group is broken in 1.14- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.1- Add workaround patch for RHBZ #1366403- https://fedoraproject.org/wiki/Changes/Automatic_Provides_for_Python_RPM_Packages- New upstream release 1.14.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0- New upstream release 1.14 beta - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0beta- New upstream release 1.14 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.14.0alpha- Resolves: rhbz#1335639 - [abrt] sssd-dbus: ldb_msg_find_element(): sssd_ifp killed by SIGSEGV- Resolves: rhbz#1328108 - Protocol error with FreeIPA on CentOS 6- New upstream release 1.13.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.4- Resolves: rhbz#1276868 - Sudo PAM Login should support multiple password prompts (e.g. Password + Token) - Resolves: rhbz#1313041 - ssh with sssd proxy fails with "Connection closed by remote host" if locale not available- Resolves: rhbz#1310664 - [RFE] IPA: resolve external group memberships of IPA groups during getgrnam and getgrgid - Resolves: rhbz#1301303 - sss_obfuscate: SyntaxError: Missing parentheses in call to 'print'- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild- Additional upstream fixes- Resolves: rhbz#1256849 - SUDO: Support the IPA schema- New upstream release 1.13.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.3- New upstream release 1.13.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.2- Rebuilt for Python3.5 rebuild- Fix building pac responder with the krb5-1.14- python-sssdconfig: Fix parssing sssd.conf without config_file_version - Resolves: upstream #2837 - REGRESSION: ipa-client-automout failed- Fix few segfaults - Resolves: upstream #2811 - PAM responder crashed if user was not set - Resolves: upstream #2810 - sssd_be crashed in ipa_srv_ad_acct_lookup_step- New upstream release 1.13.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.1- Fix OTP bug - Resolves: upstream #2729 - Do not send SSS_OTP if both factors were entered separately- Backport upstream patches required by FreeIPA 4.2.1- Fix ipa-migration bug - Resolves: upstream #2719 - IPA: returned unknown dp error code with disabled migration mode- New upstream release 1.13.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0- Unify return type of list_active_domains for python{2,3}- New upstream release 1.13 alpha - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.13.0alpha- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild- Fix libwbclient alternatives- Backport important patches from upstream 1.13 prerelease- New upstream release 1.12.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.5- Backport important patches from upstream 1.13 prerelease - Resolves: rhbz#1060325 - Does sssd-ad use the most suitable attribute for group name - Resolves: upstream #2335 - Investigate using the krb5 responder for driving the PAM conversation with OTPs - Enable cmocka tests for secondary architectures- Backport patches from upstream 1.12.5 prerelease - contains many fixes- Fix slow login with ipa and SELinux - Resolves: upstream #2624 - Only set the selinux context if the context differs from the local one- Fix regressions with ipa and SELinux - Resolves: upstream #2587 - With empty ipaselinuxusermapdefault security context on client is staff_u- Also relax libldb Requires - Remove --enable-ldb-version-check- Relax libldb BuildRequires to be greater-or-equal- Add support for python3 bindings - Add requirement to python3 or python3 bindings - Resolves: rhbz#1014594 - sssd: Support Python 3- New upstream release 1.12.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.4- Backport patches with Python3 support from upstream- Fix double free in monitor - Resolves: rhbz#1186887 [abrt] sssd-common: talloc_abort(): sssd killed by SIGABRT- Rebuild for new libldb- Decrease priority of sssd-libwbclient 20 -> 5 - It should be lower than priority of samba veriosn of libwbclient. - https://bugzilla.redhat.com/show_bug.cgi?id=1175511#c18- Apply a number of patches from upstream to fix issues found 1.12.3 - Resolves: rhbz#1176373 - dyndns_iface does not accept multiple interfaces, or isn't documented to be able to - Resolves: rhbz#988068 - getpwnam_r fails for non-existing users when sssd is not running - Resolves: upstream #2557 authentication failure with user from AD- Resolves: rhbz#1164156 - libsss_simpleifp should pull sssd-dbus - Resolves: rhbz#1179379 - gzip: stdin: file size changed while zipping when rotating logfile- New upstream release 1.12.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.3 - Fix spelling errors in description (fedpkg lint)- Rebuild for libldb 1.1.19- Resolves: rhbz#1175511 - sssd-libwbclient conflicts with Samba's and causes crash in wbinfo - in addition to the patch libwbclient.so is filtered out of the Provides list of the package- Fix regressions and bugs in sssd upstream 1.12.2 - https://fedorahosted.org/sssd/ticket/{id} - Regressions: #2471, #2475, #2483, #2487, #2529, #2535 - Bugs: #2287, #2445- Rebuild for libldb 1.1.18- Fix typo in libwbclient-devel %preun- Use alternatives for libwbclient- Backport several patches from upstream. - Fix a potential crash against old (pre-4.0) IPA servers- New upstream release 1.12.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.2- Resolves: rhbz#1139962 - Fedora 21, FreeIPA 4.0.2: sssd does not find user private group from server- New upstream release 1.12.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.1- Do not crash on resolving a group SID in IPA server mode- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild- Fix release version for upgrades- New upstream release 1.12.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild- New upstream release 1.12 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta2- Fix tests on big-endian - Fix previous changelog entry- New upstream release 1.12 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.12.0beta1- Rebuild against new ding-libs- Make LDB dependency a strict equivalency- Rebuild against new libldb- New upstream release 1.11.5.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5.1- Fix bug in generation of systemd unit file- New upstream release 1.11.5 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.5- Handle new error code for IPA password migration- Include couple of patches from upstream 1.11 branch- New upstream release 1.11.4 - Remove upstreamed patch - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.4- Handle OTP response from FreeIPA server gracefully- New upstream release 1.11.3 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.3- New upstream release 1.11.2 - Remove upstreamed patches - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.2- Fix potential crash with external groups in trusted IPA-AD setup- Add plugin for cifs-utils - Resolves: rhbz#998544- Fix failover from Global Catalog to LDAP in case GC is not available- Remove the ability to create public ccachedir (#1015089)- New upstream release 1.11.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.1- Fix multicast checks in the SSSD - Resolves: rhbz#1007475 - The multicast check is wrong in the sudo source code getting the host info- Backport simplification of ccache management from 1.11.1 - Resolves: rhbz#1010553 - sssd setting KRB5CCNAME=(null) on login- New upstream release 1.11.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0- Resolves: #967012 - [abrt] sssd-1.9.5-1.fc18: sss_mmap_cache_gr_invalidate_gid: Process /usr/libexec/sssd/sssd_nss was killed by signal 11 (SIGSEGV) - Resolves: #996214 - sssd proxy_child segfault- Rebuilt for https://fedoraproject.org/wiki/Fedora_20_Mass_Rebuild- Resolves: #906427 - Do not use %{_lib} in specfile for the nss and pam libraries- New upstream release 1.11 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.11.0beta2- New upstream release 1.10.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.1- sssd-tools should require sssd-common, not sssd- Move sssd_pac to the sssd-ipa and sssd-ad subpackages - Trim out RHEL5-specific macros since we don't build on RHEL 5 - Trim out macros for Fedora older than F18 - Update libldb requirement to 1.1.16 - Trim RPM changelog down to the last year- Move sssd_pac to the sssd-krb5 subpackage- Fix Obsoletes: to account for dist tag - Convert post and pre scripts to run on the sssd-common subpackage - Remove old conversion from SYSV- New upstream release 1.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0- the cmocka toolkit exists only on selected arches- Apply a number of patches from upstream to fix issues found post-beta, in particular: -- segfault with a high DEBUG level -- Fix IPA password migration (upstream #1873) -- Fix fail over when retrying SRV resolution (upstream #1886)- Only BuildRequire libcmocka on Fedora- Fix typo in Requires that prevented an upgrade (#973916) - Use a hardcoded version in Conflicts, not less-than-current- Enable hardened build for RHEL7- New upstream release 1.10 beta2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta2 - BuildRequire libcmocka-devel in order to run all upstream tests during build - BuildRequire libnl3 instead of libnl1 - No longer BuildRequire initscripts, we no longer use /sbin/service - Remove explicit krb5-libs >= 1.10 requires; this platform doensn't carry any older krb5-libs version- Apply a couple of patches from upstream git that resolve crashes when ID mapping object was not initialized properly but needed later- Resolves: rhbz#961357 - Missing dyndns_update entry in sssd.conf during realm join - Resolves: rhbz#961278 - Login failure: Enterprise Principal enabled by default for AD Provider - Resolves: rhbz#961251 - sssd does not create user's krb5 ccache dir/file parent directory when logging in- BuildRequire recent libini_config to ensure consistent behaviour- Explicitly Require libini_config >= 1.0.0.1 to work around a SONAME bug in ding-libs - Fix SSH integration with fully-qualified domains - Add the ability to dynamically discover the NetBIOS name- New upstream release 1.10 beta1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0beta1- Add a patch to fix krb5 ccache creation issue with krb5 1.11- New upstream release 1.10 alpha1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.10.0alpha1- Add a patch to fix krb5 unit tests- Split internal helper libraries into a shared object - Significantly reduce disk-space usage- Fix the Kerberos password expiration warning (#912223)- Do not write out dots in the domain-realm mapping file (#905650)- Include upstream patch to build with krb5-1.11- Rebuild against new libldb- Fix build with new automake versions- Recreate Kerberos ccache directory if it's missing - Resolves: rhbz#853558 - [sssd[krb5_child[PID]]]: Credential cache directory /run/user/UID/ccdir does not exist- Fix changelog dates to make F19 rpmbuild happy- New upstream release 1.9.4- New upstream release 1.9.3- Resolve groups from AD correctly- Check the validity of naming context- Move the sss_cache tool to the main package- Include the 1.9.2 tarball- New upstream release 1.9.2- New upstream release 1.9.1- require the latest libldb- Use mcpath insted of mcachepath macro to be consistent with upsteam spec file- New upstream release 1.9.0- New upstream release 1.9.0 rc1- New upstream release 1.9.0 beta7 - obsoletes patches #1-#3- Rebuild against libldb 1.12- Rebuild against libldb 1.11- Change the default ccache location to DIR:/run/user/${UID}/krb5cc and patch man page accordingly - Resolves: rhbz#851304- Rebuild against libldb 1.10- Only create the SELinux login file if there are SELinux mappings on the IPA server- Don't discard HBAC rule processing result if SELinux is on Resolves: rhbz#846792 (CVE-2012-3462)- New upstream release 1.9.0 beta 6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta6 - A new option, override_shell was added. If this option is set, all users managed by SSSD will have their shell set to its value. - Fixes for the support for setting default SELinux user context from FreeIPA. - Fixed a regression introduced in beta 5 that broke LDAP SASL binds - The SSSD supports the concept of a Primary Server and a Back Up Server in failover - A new command-line tool sss_seed is available to help prime the cache with a user record when deploying a new machine - SSSD is now able to discover and save the domain-realm mappings between an IPA server and a trusted Active Directory server. - Packaging changes to fix ldconfig usage in subpackages (#843995) - Rebuild against libldb 1.1.9- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild- New upstream release 1.9.0 beta 5 - Obsoletes the patch for missing DP_OPTION_TERMINATOR in AD provider options - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta5 - Many fixes for the support for setting default SELinux user context from FreeIPA, most notably fixed the specificity evaluation - Fixed an incorrect default in the krb5_canonicalize option of the AD provider which was preventing password change operation - The shadowLastChange attribute value is now correctly updated with the number of days since the Epoch, not seconds- Fix broken ARM build - Add missing DP_OPTION_TERMINATOR in AD provider options- Own several directories create during make install (#839782)- New upstream release 1.9.0 beta 4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta4 - Add a new AD provider to improve integration with Active Directory 2008 R2 or later servers - SUDO integration was completely rewritten. The new implementation works with multiple domains and uses an improved refresh mechanism to download only the necessary rules - The IPA authentication provider now supports subdomains - Fixed regression for setups that were setting default_tkt_enctypes manually by reverting a previous workaround.- New upstream release 1.9.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta3 - Add a new PAC responder for dealing with cross-realm Kerberos trusts - Terminate idle connections to the NSS and PAM responders- Switch unicode library from libunistring to Glib - Drop unnecessary explicit Requires on keyutils - Guarantee that versioned Requires include the correct architecture- Fix accidental disabling of the DIR cache support- New upstream release 1.9.0 beta 2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta2 - Add support for the Kerberos DIR cache for storing multiple TGTs automatically - Major performance enhancement when storing large groups in the cache - Major performance enhancement when performing initgroups() against Active Directory - SSSDConfig data file default locations can now be set during configure for easier packaging- Fix regression in endianness patch- Rebuild SSSD against ding-libs 0.3.0beta1 - Fix endianness bug in service map protocol- Fix several regressions since 1.5.x - Ensure that the RPM creates the /var/lib/sss/mc directory - Add support for Netscape password warning expiration control - Rebuild against libldb 1.1.6- New upstream release 1.9.0 beta 1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.9.0beta1 - Add native support for autofs to the IPA provider - Support for ID-mapping when connecting to Active Directory - Support for handling very large (> 1500 users) groups in Active Directory - Support for sub-domains (will be used for dealing with trust relationships) - Add a new fast in-memory cache to speed up lookups of cached data on repeated requests- New upstream release 1.8.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.3 - Numerous manpage and translation updates - LDAP: Handle situations where the RootDSE isn't available anonymously - LDAP: Fix regression for users using non-standard LDAP attributes for user information- New upstream release 1.8.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.2 - Several fixes to case-insensitive domain functions - Fix for GSSAPI binds when the keytab contains unrelated principals - Fixed several segfaults - Workarounds added for LDAP servers with unreadable RootDSE - SSH knownhostproxy will no longer enter an infinite loop preventing login - The provided SYSV init script now starts SSSD earlier at startup and stops it later during shutdown - Assorted minor fixes for issues discovered by static analysis tools- Don't duplicate libsss_autofs.so in two packages - Set explicit package contents instead of globbing- Fix uninitialized value bug causing crashes throughout the code - Resolves: rhbz#804783 - [abrt] Segfault during LDAP 'services' lookup- New upstream release 1.8.1 - Resolve issue where we could enter an infinite loop trying to connect to an auth server - Fix serious issue with complex (3+ levels) nested groups - Fix netgroup support for case-insensitivity and aliases - Fix serious issue with lookup bundling resulting in requests never completing - IPA provider will now check the value of nsAccountLock during pam_acct_mgmt in addition to pam_authenticate - Fix several regressions in the proxy provider - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#799031 - --debug option for sss_debuglevel doesn't work- New upstream release 1.8.0 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental) - Include the IPA AutoFS provider - Fixed several memory-corruption bugs - Fixed a regression in group enumeration since 1.7.0 - Fixed a regression in the proxy provider - Resolves: rhbz#741981 - Separate Cache Timeouts for SSSD - Resolves: rhbz#797968 - sssd_be: The requested tar get is not configured is logged at each login - Resolves: rhbz#754114 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#743133 - Performance regression with Kerberos authentication against AD - Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - Resolves: rhbz#786957 - sssd and kerberos should change the default location for create the Credential Cashes to /run/usr/USERNAME/krb5cc- Change default kerberos credential cache location to /run/user/- New upstream release 1.8.0 beta 3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta3 - Fixed a regression in group enumeration since 1.7.0 - Fixed several memory-corruption bugs - Finalized the ABI for the autofs support - Fixed a regression in the proxy provider- Rebuild against PCRE 8.30- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta2 - Fix two minor manpage bugs - Include the IPA AutoFS provider- New upstream release - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.8.0beta1 - Support for the service map in NSS - Support for setting default SELinux user context from FreeIPA - Support for retrieving SSH user and host keys from LDAP (Experimental) - Support for caching autofs LDAP requests (Experimental) - Support for caching SUDO rules (Experimental)- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features - fix netgroups and sudo as well- Fixes a serious memory hierarchy bug causing unpredictable behavior in the LDAP provider.- Resolves: rhbz#773706 - SSSD fails during autodetection of search bases for new LDAP features- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild- New upstream release 1.7.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.7.0 - Support for case-insensitive domains - Support for multiple search bases in the LDAP provider - Support for the native FreeIPA netgroup implementation - Reliability improvements to the process monitor - New DEBUG facility with more consistent log levels - New tool to change debug log levels without restarting SSSD - SSSD will now disconnect from LDAP server when idle - FreeIPA HBAC rules can choose to ignore srchost options for significant performance gains - Assorted performance improvements in the LDAP provider- New upstream release 1.6.4 - Rolls up previous patches applied to the 1.6.3 tarball - Fixes a rare issue causing crashes in the failover logic - Fixes an issue where SSSD would return the wrong PAM error code for users that it does not recognize.- Rebuild against libldb 1.1.4- Resolves: rhbz#753639 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758425 - LDAP failover not working if server refuses connections- Rebuild for libldb 1.1.3- Resolves: rhbz#752495 - Crash when apply settings- New upstream release 1.6.3 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.3 - Fixes a major cache performance issue introduced in 1.6.2 - Fixes a potential infinite-loop with certain LDAP layouts- Rebuilt for glibc bug#747377- Change selinux policy requirement to Conflicts: with the old version, rather than Requires: the supported version.- Add explicit requirement on selinux-policy version to address new SBUS symlinks.- Remove %files reference to sss_debuglevel copied from wrong upstreeam spec file.- Improved handling of users and groups with multi-valued name attributes (aliases) - Performance enhancements Initgroups on RFC2307bis/FreeIPA HBAC rule processing - Improved process-hang detection and restarting - Enabled the midpoint cache refresh by default (fewer cache misses on commonly-used entries) - Cleaned up the example configuration - New tool to change debug level on the fly- New upstream release 1.6.1 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.1 - Fixes a serious issue with LDAP connections when the communication is dropped (e.g. VPN disconnection, waking from sleep) - SSSD is now less strict when dealing with users/groups with multiple names when a definitive primary name cannot be determined - The LDAP provider will no longer attempt to canonicalize by default when using SASL. An option to re-enable this has been provided. - Fixes for non-standard LDAP attribute names (e.g. those used by Active Directory) - Three HBAC regressions have been fixed. - Fix for an infinite loop in the deref code- Build with _hardened_build macro- New upstream release 1.6.0 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.6.0 - Add host access control support for LDAP (similar to pam_host_attr) - Finer-grained control on principals used with Kerberos (such as for FAST or - validation) - Added a new tool sss_cache to allow selective expiring of cached entries - Added support for LDAP DEREF and ASQ controls - Added access control features for Novell Directory Server - FreeIPA dynamic DNS update now checks first to see if an update is needed - Complete rewrite of the HBAC library - New libraries: libipa_hbac and libipa_hbac-python- New upstream release 1.5.11 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.11 - Fix a serious regression that prevented SSSD from working with ldaps:// URIs - IPA Provider: Fix a bug with dynamic DNS that resulted in the wrong IPv6 - address being saved to the AAAA record- New upstream release 1.5.10 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.10 - Fixed a regression introduced in 1.5.9 that could result in blocking calls - to LDAP- New upstream release 1.5.9 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.9 - Support for overriding home directory, shell and primary GID locally - Properly honor TTL values from SRV record lookups - Support non-POSIX groups in nested group chains (for RFC2307bis LDAP - servers) - Properly escape IPv6 addresses in the failover code - Do not crash if inotify fails (e.g. resource exhaustion) - Don't add multiple TGT renewal callbacks (too many log messages)- New upstream release 1.5.8 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.8 - Support for the LDAP paging control - Support for multiple DNS servers for name resolution - Fixes for several group membership bugs - Fixes for rare crash bugs- Resolves: rhbz#706740 - Orphaned links on rc0.d-rc6.d - Make sure to properly convert to systemd if upgrading from newer - updates for Fedora 14- Fix segfault in TGT renewal- Resolves: rhbz#700891 - CVE-2011-1758 sssd: automatic TGT renewal overwrites - cached password with predicatable filename- Re-add manpage translations- New upstream release 1.5.6 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.6 - Fixed a serious memory leak in the memberOf plugin - Fixed a regression with the negative cache that caused it to be essentially - nonfunctional - Fixed an issue where the user's full name would sometimes be removed from - the cache - Fixed an issue with password changes in the kerberos provider not working - with kpasswd- Resolves: rhbz#697057 - kpasswd fails when using sssd and - kadmin server != kdc server - Upgrades from SysV should now maintain enabled/disabled status- Fix %postun- Fix systemd conversion. Upgrades from SysV to systemd weren't properly - enabling the systemd service. - Fix a serious memory leak in the memberOf plugin - Fix an issue where the user's full name would sometimes be removed - from the cache- Install systemd unit file instead of sysv init script- New upstream release 1.5.5 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.5 - Fixes for several crash bugs - LDAP group lookups will no longer abort if there is a zero-length member - attribute - Add automatic fallback to 'cn' if the 'gecos' attribute does not exist- New upstream release 1.5.4 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.4 - Fixes for Active Directory when not all users and groups have POSIX attributes - Fixes for handling users and groups that have name aliases (aliases are ignored) - Fix group memberships after initgroups in the IPA provider- Resolves: rhbz#683267 - sssd 1.5.1-9 breaks AD authentication- New upstream release 1.5.3 - Support for libldb >= 1.0.0- New upstream release 1.5.2 - https://fedorahosted.org/sssd/wiki/Releases/Notes-1.5.2 - Fixes for support of FreeIPA v2 - Fixes for failover if DNS entries change - Improved sss_obfuscate tool with better interactive mode - Fix several crash bugs - Don't attempt to use START_TLS over SSL. Some LDAP servers can't handle this - Delete users from the local cache if initgroups calls return 'no such user' - (previously only worked for getpwnam/getpwuid) - Use new Transifex.net translations - Better support for automatic TGT renewal (now survives restart) - Netgroup fixes- Rebuild sssd against libldb 1.0.2 so the memberof module loads again. - Related: rhbz#677425- Resolves: rhbz#677768 - name service caches names, so id command shows - recently deleted users- Ensure that SSSD builds against libldb-1.0.0 on F15 and later - Remove .la for memberOf- Fix memberOf install path- Add support for libldb 1.0.0- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild- Fix nested group member filter sanitization for RFC2307bis - Put translated tool manpages into the sssd-tools subpackage- Restore Requires: cyrus-sasl-gssapi as it is not auto-detected during - rpmbuild- New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options -Assorted bugfixes- CVE-2010-4341 - DoS in sssd PAM responder can prevent logins- New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Solve a shutdown race-condition that sometimes left processes running - Resolves: rhbz#606887 - SSSD stops on upgrade- Log startup errors to the syslog - Allow cache cleanup to be disabled in sssd.conf- New upstream release 1.4.1 - Add support for netgroups to the proxy provider - Fixes a minor bug with UIDs/GIDs >= 2^31 - Fixes a segfault in the kerberos provider - Fixes a segfault in the NSS responder if a data provider crashes - Correctly use sdap_netgroup_search_base- Fix incorrect tarball URL- New upstream release 1.4.0 - Added support for netgroups to the LDAP provider - Performance improvements made to group processing of RFC2307 LDAP servers - Fixed nested group issues with RFC2307bis LDAP servers without a memberOf plugin - Build-system improvements to support Gentoo - Split out several libraries into the ding-libs tarball - Manpage reviewed and updated- Fix pre and post script requirements- Resolves: rhbz#606887 - sssd stops on upgrade- Resolves: rhbz#626205 - Unable to unlock screen- Resolves: rhbz#637955 - libini_config-devel needs libcollection-devel but - doesn't require it- Resolves: rhbz#632615 - the krb5 locator plugin isn't packaged for multilib- Resolves: CVE-2010-2940 - sssd allows null password entry to authenticate - against LDAP- Rebuilt for https://fedoraproject.org/wiki/Features/Python_2.7/MassRebuild- New upstream version 1.2.91 (1.3.0rc1) - Improved LDAP failover - Synchronous sysdb API (provides performance enhancements) - Better online reconnection detection- New stable upstream version 1.2.1 - Resolves: rhbz#595529 - spec file should eschew %define in favor of - %global - Resolves: rhbz#593644 - Empty list of simple_allow_users causes sssd service - to fail while restart. - Resolves: rhbz#599026 - Makefile typo causes SSSD not to use the kernel - keyring - Resolves: rhbz#599724 - sssd is broken on Rawhide- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code) esessvsvukuk2.5.2-1.el82.5.2-1.el8 .build-id2375444307b435bd5550dbdf3b8871912cf468f5libsss_ldap.sosssd-ldapCOPYINGsssd-ldap-attributes.5.gzsssd-ldap.5.gzsssd-ldap-attributes.5.gzsssd-ldap.5.gzsssd-ldap-attributes.5.gzsssd-ldap.5.gzsssd-ldap-attributes.5.gzsssd-ldap.5.gz/usr/lib//usr/lib/.build-id//usr/lib/.build-id/23//usr/lib64/sssd//usr/share/licenses//usr/share/licenses/sssd-ldap//usr/share/man/es/man5//usr/share/man/man5//usr/share/man/sv/man5//usr/share/man/uk/man5/-O2 -g -pipe -Wall -Werror=format-security -Wp,-D_FORTIFY_SOURCE=2 -Wp,-D_GLIBCXX_ASSERTIONS -fexceptions -fstack-protector-strong -grecord-gcc-switches -specs=/usr/lib/rpm/redhat/redhat-hardened-cc1 -specs=/usr/lib/rpm/redhat/redhat-annobin-cc1 -m64 -mtune=generic -fasynchronous-unwind-tables -fstack-clash-protection -fcf-protectioncpioxz2x86_64-redhat-linux-gnudirectoryELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=2375444307b435bd5550dbdf3b8871912cf468f5, strippedASCII texttroff or preprocessor input, UTF-8 Unicode text, with very long lines (gzip compressed data, max compression, from Unix)troff or preprocessor input, ASCII text, with very long lines (gzip compressed data, max compression, from Unix)'PR#R&RRRRRRRRR R R RR RRRRRR$R RR RRRRRRRR%R"RRR!RR*utf-819aa52db378a52b8c810753dfdc2d2e43a0d6b82eb617d3f7941d536a37d8dd7?7zXZ !#,b] b2u jӫ`(y,y/ܬu xOb+Յ:Tbmؕ1|͐R9QFx I> VQ02嬫i2=ug=(3$ʮWmŶW׃>Сnk#7+'^<+zHdVvM(IR.c UY?"M}V. #Vf\2^D)J1CHK\;%)rekْ/L:"XFQk%5NPxXgF9Rfߺׄ0W0:~y-̉#G)W-F?Jd;k1P+nijӺ2'%J.|'"؛LdPĀDZxpg!" r[h*BOw9o.wq{QIðx3UU$NPUuk?[ sYQA5? g I T(~r6jݒE%ـ@꨼4=m8cÌWQ9/c-UvGݺ,[IY"?9Aۛn2'QT4XOWem$}4JZkVc{.5mEe [U⺈CM}JY zՆUJG/--5jU\ ׫><.V}aՋ 䏰;~֢6d]Z~ AiZV(Ÿ ն^[p-#zM8CF^6{e_a᠏1:K(l۽\650}nLn>ڃK*Z;M KewaB=V 㬴ԾİRdܲUkli=xbu)G^ ۞yt{,5B8ag%55uz] h`ko,g ,*.dpIcG-)ߕ8PSVSV١ YH9WG*S8WZw6M%Aqy@l >.~ 'e ҨI*` jj{6M L:%[,骫 FJ(BvwکQ@\@-$d.붤vYw;ui([ o9@zэNt>mǭ|]Jկy=K V*g; [rV293 yN#_k%U/V ͔EUpl%)0~ߤrRsEF/?~RʍE[E@D;ŃWɞŚ;`9tn;2 4P0`Ƞ';_+Q? Ų@5dBNj2s2q͡ g n-VVgIh8!K7Iyۯ)Ô»~YrрV/Sgfɕbn"1TʭR&Y{of(9-3Z 7Ow#Tc=1q>k[w4m#X/ leLdބvvZ|?3`@X=(K;g W5'o'd6ᯃ,G8`3A3!TEd|"W,Kmk8a C!`8 8_uLAJ(ًec'W5t?k>= *7$+M֕?v9ڰlq"wzgC[ gDYb,j:CA*lXB维tɊ|@TRVǩilװ~A?dv}R4 6 'L wwZz'E}rI39>d9-wsƜrM| !)썗a19MnaKĸ,>b=!KI~+CլaAlǍ76I̝?ԪJ1 h!a>|xp zoaSJ̶"c kYǡc$xwzf?wO=$>1ȍ 2ŶЅ;#\v:ۧ 5 #t&{cHk迻\{,͌V 7'MffYۥ ,o5u94EeX>Sgua8cB T&26(t_C%v~H@v1ΤFxsM tލ!4hJ8Zɡ>7L8/[wøvUT}]Yҫrɼs7QoB9g@BP;JjV,m2zBdFġOl0=c>vCN]΋YhK;ۖX~uUq=4zτI.S1}'8Pn."pR8/DM@[);CFqи{>I;DZ{u;eD3P2:K4CJSX"j|O&}V6` عu^$jp@Ԕ2pKy Ғ`),X&۬X\]8'u`9D<40>P`;y- ~d=!7;!-~!8 Wﻱ:Qaҕ=|cn>vsU{Y5 w_1,MTg DQ@hؐo&.}S܃izJ0 x8 deg X$tx Paz &$|^Nޟ<Ϧ}g|}iaaU~b~~YT1d> Iz[LXAWrӗlslfX}u3CߐAewA.h"a&G̎/'~Ho-3K[ W̫y8@\Bi#tv7SpݎiGzS@G7T.a:@Fm ;K){>;7@T!\A(4wq$QAQ%׉g!!z"$q(Ѡ30^bMM%۹tʙ48ܻĦ,Zn ڦIo]!wJS2vd^\ӵA`+}W|e Qm='Ul?[c{}\E_q3!ecI9Vc(;4{v//m:۝)9;FCbqo!Ms| [9=Rv/vTj@A33Kq x1Z~7BQҝ"+Uf[M|v VmٸT3›k[.Z!aÕT8օhؚu^6ƿ;38jfܝ?#HDnńWe>(EU{3= ΃UoUS4^o2:7]zr#ye-<{-P=c狡l1kP`0җ?6P6j*ÁU8# -.mtXFլz7τ,j%ٵEp kݰ3o# ǐh#=yӔǁWw.'-j˰ aszzT4khP]4^ _Xcuq}k*g5qR\ Mh1֖kԯ{wmdRC2w_?$r" VCj!Mvc#q:濪tM*S} [R1ߤ.nYr>mFnwm C /xQŅgT@Dž0UCF̡ۏj9w<5]l+1i@gtS_om;0b?۶QO2V_-Mmt$##\7nnT0ruF¨k,[Pjܲ#~֖GyPː,!Ǒ> gl<weFJ\!LAٌC 1 vwKw ^P"ϞV P/7:^mBVJ)7)kޞ>}QVf+|d[T2r<[<_xxXggu,k`d-JO,}2+8QCrtHR]-_bq?]e Rsx ?FI)q0Iq "3F S@EF_1J^r~0Ͽ[/!m *2+l}vn%Hd"JvŴrOIDk=68-b0} Cpj1dt꟣|2* ^ )b#`Jwv#ITfhpFss 'm'ksp %qmo'H6`Coqn|CAtl+G$R/ Y}D3M'H.4/SN) @%ֈy$Hard}WzžwZFJ7~I# j>LʣD?,-i]a|5j>KcT27ah4D#.:ٟ(薐@m̲61ͮ2_QJ̻#Ar+RȒ~bƨ){sav8TZX} k %(ՊZj$pτV.CKde߄dt(Z!W/5x(WqPJ_]S (KNU@3 ڝ֓غENa%/4݋$ abL層x#'ߺczFc;A 7j"cRPI%r krd es̵=0Uw\ה| \)\ogp0[zwy<*2֕r u;o&VkBްU6ɹmR?iia?N(a- NL*4&kNKe^pƬ!Qc"rNs류 : DBHdmՃX_ >F͒i$p(B!n=`px?ѥr݁Y0@!k+CQ'ڬ`kpuH39? V~`ч(X7wf֩Xj?Y[YSC{sxM$:WQJ%}pҹ[0+_T=eŕ\G=u̸y%ƛ60arttMG*<{ULv #<{ٔ9,ʃL7vix>{{a>~M |:<_6prl넗N\Xy]ZR ai=T]Jka^8d6yeӃBTߥIސ#;n}4:< }SjwCf"D}Fc0n!Bt89;㵔LS49 }[=F'MۑN\>TBY3ea9SJԏ, ݂d5;#vSG7g5:>(>HQn+eHY2eo$1/Apԩ]+ @ @k8ϿʁDYi6i-ߦ֌:СQg%Za+9*Y!*ØJ.IQc@TH||ItwomzaIz_d]N:WNȕDpb3V&~OU<>҇&w@Wvˆ7(Leob980c0Nt{ȶËlq4Y|v{62hGR&1մ)B0ڦ-Uz8"?Ͻ`5 ƚtlIdv]W-J'.<:}}(ϣ tl~×ArF-Mu\X\Гȩj叔|[g9}lJYHJǐmXHm6MLi?-kP my/c4T=┃=نtCz3O #? Ok=kb?NM#jiȟf%]qџ!l|ehLN֞Ɲfdn"?:rhPLk g y+l\#V'ihgA%?*z4%l\N -Жe(g~%>=ֻ*(N"qӳ̤$?mg2݉Y!Ud%X)bTWgtx%ZrsL$BSEz%^p臭)Qv֩˳3i?-;c}289g Ya7wm9e#魱j YF<u%Yگ]9ar>MIKlo*EiL֔IgI H ݈%REm4 eu ݒą@dSur37c oadP%fO6"H ]:|tkB^E>I|{Yƕt oU5C=KLZ@`:t¤Qh+=: fs̭UHm6Dz_ ni~ 㱮ը]֟xT> ht,Zԧ)Dpj:ZN7 t|e!䦓茶о?Č~&T|xQ=3,Кs>8Y)$ۭ冐ZmvP(7QZU`䆵Qp8205q8߼ZC]Q+v-1L#Xm׭TRwƴn:? us'p lLh#s~մԡs q}lxeTOb˃ӌ7I3SSRAwLf`W:S.9)H)FzYl_ &8\ -7b שv8&;#}78#6&0bO9O|zMGv9h3#ʺh~U.9;wgzSa4et! #(kң)+-|7t:ۣ y!7.eB#5UU|z`}u<8S  Q>:Y\q d!L5۲+;3iB7ũ%ϟ:*uCĥ4z+ 'Gd 2~1'.Ҫ*+ dVB+! 5?~,'f$Cծۉ3!)|' jKq=|<ÙyPM*#(țٴm4؜.ގͰȶ97dc dm7K3V0ow4<̨CjKؽ$cy46`6 5j0g6ٔ.ZJs~w5mlx֣iaa?/yKdNxx ,1W% .?ރ(e~<|:5_UeAa1~3*(ZͰArkRq!S"M$ȐŜ]] IG7 ]L)4䬓M˱][;^@:pM). CU'\hk^"ܯa_]oJ6~'U(`',M>A34陽hGp]ey4TNY`dIk2_/?3r"hl#֬zcƨ][Qu<(0#~:|*t{L%XqWnfb\_6K+@$PƢcq{{s!VzJR2u݂HקIE&It-' K!FBi -Lm n޲` lQ Ff.L=衆~Aw'h?E*TMwJPJ$5K٤nZuQIb0pΏt23Kq;:r,{bZ"|(`7p8[e # a 'i(H#G֔J8ג@Ʌzxfw#<7vq0 c% fh0Sy9'hcEpd#Au޴,Qӓ+ mONAj8ntY_Q&:UetJ='@ѵ oz}/V9;]3:TB7Df;l,^+Cm(v'f+IXh(X;eƛ+Wic:-ߜvuy"A!dWŢ+%><" fN\톽m,bcgOSϖa ( ǰqp[YxtώGӫXL,냐8r'Aյz/N7ygzR"D[:a;QڱNgPyw0tK+$2H=|A`ZHYWZ(PA5(p\Bw dcsG˭gD).,yس `P^S{=4,־}2TZTc{;Ӣӗ6'iBnؿJ~~5J@^AYrqe6w6'dz—y:=Õ.OtzJ ϴh-ԕG}ړ+KpQ|ZK󗩉8r?i)t/F$n ^}+&] *cK gOx~3p.M#(8)}{{Kԟ;.R' "-%+fE,>fH6ߊ n-B1Fgˬ ^[{kz%v?!qiI9@4]ll\fI鸯2j18)7bzsi ODL'YRB\k{_LP{}GUңn}äϰ:X\*^q1߼>Wij:p`q-ˏta~1=P,dLa BUu&'xV PRDWJS]XL _t,T-ݢ.n(+>B8)bdDx^pe$X.@}o,BGa%wJɂp]X3,tT*[!" 2!oNdKt1A PJcQG)__"eYhD*OE&brO1dꘇ\L @uԣR~P'yI1#>YVs@]-G0q#âwV<|6^%I5yrr"ŃXȵQJM@ s;"}׋5刾?C.K4SprٽP==6e0!-q a\)'h<фdl#?{43@umUVp!=Jy[^QI(2ϦhSX^.0XxEZHDp-Ǹ@ o\dVjN+wTkyz0`pԡsJ8R> pLe@{<%fMk ':RsWۈxlwm)W(B&J_,"w)Qֱ`=m2OG0n.17@1C9U¨0*DTKGGuI_Ѐg6@2W&B8i\,Zzk8\! Ð~ Z gg~*` uI(.8~[iK!KY'UOκpMb=>{'V(ko*S qӨ<)*yY7M DhU(_ v~*)' rv&2܌ 鸛+ 9tbf%, C\8I&M+'R%(b+/}ܞΗ 2WNKzyDy'|;DA${n
    jG>դ,A?-gl$')RɄ| QTlISPn*:^?x{0 X[ygoxtrĹ3tOD c)TT1AĢ;4Rtfijɶ/\l2%H?sDLEU9fxk?|𬹕KSIH\" tz2c]j%F_zj!E}!t*G⬡v3 2,zv6>`&›+$Aa3ޢر^,]䕻c^E}paTf}a+U0_ly1j Jg>@mNNqwrm7INh1^0n? D 7qBjE $.1QhǮ]s9C ѧc>NG~\: ;_|v_=X1` vp`2|?\7S5FE_[#]C7-[ا9 JB{0="a.Ag#6~E0HHU@?BHwDii2&VYJW&w<(θƋB:н+S-Rm4C8Uޔч lL;B3rb'KS43؎pXka+̾|ܰw*[I؉BWO(0tj쉉ú#Q -T5Ϩk} ԥnI F'-uwk[%壎 KF\%vMmqުf),r߈}9]"x.$׾Kk{XOw=|փ.ΉA˯vǬ M%) WhѴ9#eY1AߛaP4- CH?:P!%:{f Z~P&w\)nܓk lKZ/"q ,z gl=LT <v1Ҙ#$+inȡqT IP@׸z@5hHcktv;\M];J&MbctwmDz[jй[1`s.(P2p`D=PqEY6$:%^?DdC 6eh2*dy{^ۜ$fslTyBqD罱H0n{r,$ u芟MFT_ N%C8ȶ! )[4p:w:?#M 2wU&qut$)-^o]K@FUc$Hϼ4)%S)1ѐ_`7fV{pӦ%i18m:Yäމ6|﮹ ob(wإvc$xbrk݂-%0щ"N\}Z3Q52Rl8_bV&{טaB׊GQ9d\pyHtij4)32=(0boL"xh)$+SA՞7(LEL7%3t8B5}GK$2<g6x'Q'kXAZD6d}62CRo6c%T5% # {Z4  cRamXu!lw(W7k$wGwݣCgiZSK4c'v7L/K\'Lj"9 ʶ?pEݑH]WlMR{mV1?ȐBrPXX߰DM<aZwzbH,j &Wdf((pM(I]R _$Џ<\$Y$!:w~BGѕos%̮Hjߚp`0hi\Kv?hg]$yૌ 0m|"./#fƝ ֊@™*HLK|;! z+d ̋i"1OP0"\n})?؍ ^isc$3i"ؤ2Z󹱧C(17/{WM'Ý )⶙ OQJ^46QOy54*6 Mj^BzJUrIv"WYM%t+ ny KuS/Q'pZ)Ea,HiX'jʟ qtM`o@-Ȑ+e2!M;,f^02H:X>;p)|<uUbVş/!!5 Ȩ7ofXjNTVS)x~i (L3 JMo$Y)v?YyFy`:(G P,!HOެQՉBZ;PyaW+sy֌J{e̟%tfqGO7{4h40";uI3ΰ k?5bIHMαϟE7@JK VQ́ ,fk UP'MhYHΒ ^};JW)mkr"vZDAbsm N=S nBI)6;IS'$Ʋ,Ml4@S*d?XDmB= jAs0zƞxsO j B-kVyx/ø4!]%Un[-R ZrPW j/HvO9#4bg,0q_4+5-ؘ#-VpdpYlv'ZP?펪O¿"=M;*ˍVIĺBUH'W~ K/m%o`{O#OpIAyҫDչƯSwP:6"3wv7[ӷOqf:_i=;۔.%D],RC3*Bͦi:%(D^SYṎP{ E7Xbvp f8:ܔ4dҭ[X)0<)c[ sVQL7!+E-)Oݷ}5 Ӱ`{r͆xc=S)eA'ܛX1ǡO. E߹JE8]Lys|[:ȄUokyaf@-Zk{kMYՁ( [3 H9]?ﮍi0("agP7MCr<@"N'aKJR6]+5q:3~(>x([]M80pBcH҄CӘVE~F%)iއ!xllqrvFQy;"&9\<I}@܅_tW騽(szիـUO:ˆ g !RzUTwx6KNַV5C1գ®^ta~A*P.nR)X!DxY03J/Qw?v^qk(w}.rV⮳ ־,l $I,Q(|s|ǮFڳ4CY LOx&kJ!t6,K+t  ՘(o!,z V¬zr\=8R\=:@cw T1?dZ^S6,/O!1R޿ 3j^۫]Rt*Us}'Tk|YHqqpX9Re>j,KdCGǥ K!ᦥ@i !ˠx5~->9)=mD $: >#"6/|c}TeUIi :o x]&Iks?9pI< ?ѐT4x&+ơ6:T l-oٱ'[!N.al6Br pB.!ݞ(vA9\gT~E4O};0K=!]W#8I*tMi|/^ rGA;jqҮۥB?MV]P FA be''k7O]>>;y[5Hdj5Urf\PU!QdЭgquTc@i7SE}8^,jGfnyh?c5\Ƌ U"*J)wnI02Sa?|S/5WöIkۺ米b!+.  Eս_"=a$Hޚn/?O{Ȟ v=պ9W*CZ:3[ :zNP;SO1³{ Iu%)yD6p9\$p7}lE:T)'F[x# _NMEV͕!f`OKղX.RܐE .m"*LARSн!0#Log̣OVFp=85HH'Nr 2k!?B>^H$'*UU^[ceɛˏDL^SA7ikǙ5.slR@gt6Ve+iL~]MWF5u6'sU#;~:љh83tή5IZ[E`ۓSmDZSTvV!>X,C Aq19aRzhXCq"lBk~pبϕI Ⱥb< YG8.jD|Bq) (6i^1W() P;mAWrWI BSa"mF=AL`ٷyE 88|HZ+aˎP V@ddu+^_*m"8< 0f)\<=wD*e\gh0nNٓcuLfS 6R @~pJ}RW1c2uŭie+'M͗}̂)D R5d8? 0Аvvz \FX#L /F5}R$,؂9=kk\,8|9e+Wwo5kl&+Ez6a\~VV!cՃvE9CL:{5<@})ÂP9)aw9C|a6>2lvI,L (qUh.87H \sNSS1|OT׃c=19E|}&9k 1z"tne!f!7䆡Ce $;WfMD$Wcj5ؘ4Ƴv[jտƉ(ؔw I@GlயJa`ꝽJ|`;oY̯4Y\ ~r6w@ /ZKoi$1W'e}` .Sk"#M2淬H=«zK{z6=Q;݈cD0-רf^W1| ~vTunwZk,1@zu#'`CaP+MQ/%fO*PP! 5:62O*ea ifFuL#PO]Bi < Mڲ/9VIg!0*HHNn"+IÈS oSoịGIbظ*4exJ,ob,u="0*]n:4nU$Sw?WmQ5ZNj/hkYۨNcj<Ȳ D?ꯩ<a7 HvA(]{0>FQ6(vl;QflC+~Ũ+ԩ(7Kx w6[zHA1h@lp]kJfpWln,lɹbifeCb'󵣒$ 焮 a%C' ɳsN4U3^p-q8Σ|BίѢYaش/>J’+pkS;8ӿqDCui\JjArΤ3d9ąћB7^4f[uWtaci?᭎ZT-KI譠!mnya[ !`M66VSz- X!tEQoOdAxgeHsC9L}x3/@U q@뺮J@T9ok)m*;G[]G|ߟ>*-E)/2yd}y((Uq8 b}0/1W>Gne5ȧ'NXq-qaPau_OH֥ikܸkO^hǖ'=k V!ވ4Dy3\EvH E8加܉9 V|jTbNxh'^.իf;.QZoɳz_Pس iJ[Yg㫿n+RBuZ ah=޳ɤKg} 4=1/Te.& q<}hyP4L2y& lOLHRqvLܯ|g-6.mP;(ɋԴ ؋+ :q oDC֒gPf/}X ! %r OHJeZk*7kBoHk؟!ݛ:t)дwT/pASλq(cBi)} :ܞ I[y3cb`~ׅBOc^򎮯 r\Ҡˉn[+) mi^௙E9өLkT{JP}ug=mMjIG5掰A`y y*MȂaԟ@*Md`q';Dj<tp9@qB,+ǃ6у 6F%޶qT5>NaM@?&\C!kQ6-I|ԕ> OBRL@x3 #j+x?*G]^ʭ.SmʛD ndA 0qjfk[Lc; Bd7իd_F1ڽ-5_f,qKѽ^ɣL^PcH>`6)vţHhWMk99QCލWTF ,eAۿnzut9^ʹW(q0(#iM6F4οv'4xI2&G[[jƟKm|{XCV:XSccM `(iHK!1xb1~4;A ^,0yt4D!A =޻IsN$@`آ ([4-W&ӣ t5ק-n}K\{YMQ}ꩅMyXCM\^^M]GVcǜmtk߶OZa]Y5ZȺm177~^%!JNDQHU=S_y&Wb2/SPZJ8s%aOa; V`[cF0'5ŠYlkGQOpyd˱\(P T` qvba $n1yr8 XE}"ޛ-+CGQ("7EJpg~6e}X nY>M+ˋO3Ŕ +}5D*@&P^3ްlhQҌ yg4^=~' 菧//<5R_}g1pq~wky$^E$;"iqO1rH^BOjapM I8h<(EqR)*GEA b^j W"JJsy9AҞPYdguH(t^;ZfrX@*` g@nFJ]gOјͽ aߦ$"56~,6~5ٺb7A?LϠt##=- #^ 5ɺE%6,:X}l1Fwن*+ړM"aiv~_?zm+V? He뉲3^pc\hyA_i j|}[gk6e̗uO$@Z4Ҫ_aXo"ra_mA%>LGi"@WĿFat=J]=tEs;TreOHkWCOfb RTҴ&lZg?hKmۍ1y~xu5;>ETGk' 4\\% ;Ւi?&ׁ$^1u6  4Q9K& Sj\~EP9%wXKf  ! 4g$8 6s`rŪ y):V/r;!! 6BGJ17 {k+m,,UHԩeC$G2 {^sV9?<li*h1fU8H#DRO7X,[#^V|m<)eN2k ѹ.L%Ms"z0Tu < !.\t` )^HOP|T*#Winj[Y5W~FUNΉjIz? jsiǜ'_etwn"SڀݼȾ Lx^J2Tχ"ȏs^` I< ƕ\u*9bҌ՘\*)֣S %H.D*";qL@L*V8kN{Ud5%ubQ)7lDh TnA>u"\=vԹ x;GOSYs5! r?r4Q@r!tPbN8cof.:@Hbܦ;TcArEA~ S;<47y&Ef,kT2g=DqFVbI9+$PspL$-G=I|Yʁk h !lBugC hs\pWJa+T[ `)c6mSy .H3 6۞{\6C_# tTl`@SՉʘjK<8U5Mh8m%¼_bݑ|ݛH8O1S.ovU:B'XAPESi?nm1ͥ֝\%E" 5ݿp!5H:Vm4q܇pA!7apQ!vz Fvq z}TR@mƠU @ٶf1 Z>.7*Ri [NB?w.ӏ*!yIOOآ&@pbUC|4 ~5*!WkS( 47[ 39Ĺcr ^lJv _%, uSEsp8H\H̸,wqW(qnDtKVHC0 d ww`!7 3 M6Lv|x31Tt _b=rHN"P}xWu|7.ׁsl8['C[foBӥpqai1Vs )Kn`rGU-k>ꄴaOOρ< L9VTWW =+0o{dbm<% 2i1l,=PWLJMN8Gƽ$F(0:Tz0-US_6ʁ>HdBLy7(݃:meOX蘈BPllB>;wZ7~ Y-c^B,`?6XeQ{H ËV`qnLX%1{&t"kGK8X(FQs ëbEJ| ؗogg:;"@VAC rHnS1`Ǐ\_~|nGc ˕.R6Jǥ}-bL4ŽьOGnExlRv1y.n/r` nXK٫V7zIR-R5$6}؂JPpïHrPGeR\Nky*=3gVZ<Ȣ:dNbo6뇞-0:\gٓobP^ rӫB_8bDpwuagJGq~vЪ0Wi`7̡#oMz)hAt7)ZfTcZ]ۧttd7SI"EnܣpсUNYuA)h -\s<l, 6Xo9N.()g omgi,t0GѿCY^HFGd{I:7R0=_9Lݎ(A%0ļ|sڹ?%:_ 3p6kQ2 A+OakM\i*hUש7΀5 n=wۮ^ca!txs2s46Ôzgg[l_l~W6 1{fOwuTk(dWyۺҾJN>})Eo\'[5Ve LcKJn0Wρ;m$nxSOih'yc_b*vɢ[rHB/Q vc(7@316;Ttwr̳ C?*e0v@(X0+WF9f.0Uw@n9ml_[NKXPC9ۣ6d~j50^PFi3ipcdfm ]C˪q<;27DRKgGQ| 0mӎٖ%M }l{(pJ, dŋ?̱ 4 '`aܚA|njؒ-kRF挪+kl5<]5xD5K}`xɈFl/rs>uFpwP DPi@bjn`C*]" T$-y{^ g;l&-!=Ƀ0<^e&o ǻh6iq+1K41(+?{/ҡCqyr]ףN'8_2ݿl0lpտL -LR_p"0!8iClg).WL8tȠ5 gsbm%R!oGKvoG9W u<'CS67{v6L6.AKO]-icm䌟a[hC,yUL% @}5QӕB]8&|qYޤpv믑"\9? @֘^%e%,ƝFk%6g'2,x(-.v_~ؼzj&"? WSqPyV q/xTᛧG*o X?gQ XaRTSnɔ}/:%" [ymoJmJ^+Y<ᷜ: Zf@`=y2dhoQQF3nPF^;67=iU?kD@M|u/C+4'7 ]3}\/n`L~Hȅ$k[ƒqR,51^m-UXDТo9uHq8Pw3kB"oW<6-H3 D' Yy*n\} +}+);$tOA'>-SZ8"vil(<~bE_3blr(63h9q4y(cwN7+ UD6jU,,3_1||N.OբWu"4. dL0S%PV3a־,a#TKZlqRh <߶hVX6=^<\B&M+q-,eBZK^a)^{ K<<IOkm}ZbD h,o|+cQs6;d^ɣM<=ZP0){B *r7Q7p`'I;'IFi%8"h#C`zr1<cin SA!"6mm),F e9YF%8,U1h*~47P| hyEaÎG/*W͇7W[.$+e7ao+~I/hD8  Պ-g>tS$T]-+cK]'_h[2ġsiāZifEZSRE8Pƴ'& #g8>I' [?O߯D^fJ~'.lM$L2_FV2IN8j2ܿX*S6W|3qSrAaf!C~!N㲎-;^oeSXJ};?xMB"gb=< bD wK#I[TS&D] ;8Pkua/L֦̬ 7/?;Lu0POmfp^4:.BB %Pb<;"f7Wy~$Q)Jhr\l&@3M;j{vFU/}S>xrsvEi:5CF_Y.:ZDhC jm gu"T~' t4 "qQ}9O0z'u(2$g!Hчn; {־hBi.G\6EɰSV) in٪-E-]%f/k{ P\/HѤm%E t glyN~Wٸ$2:#]Uh`T[6!8:i{dd6Sችxt +Ɇl#j(|*oкz]nemO^:N݄Fp(۸KC|*ϡ+)=NV5wi_|{Qu $d LXɔ,kѶ# yWZy_4d/s~|!B|iraA ucoZNzݡezctSzUfe#8>@.y&4Œ;ѼqDLAݜ0ܴ/bs2щL\u #©`9gG*u{Wjze앝`_п/uJjaƵO|?f Qy\ P|ʌg>aUl)P\wfgi>ۍ,Z aIR ۜݣ1n Lx= )Facڞ̒G@c':s/^_I>p")k{?}31Su=k|73"v,t/HtnILHTH>׉KZAHCID>2-Q+BƮ+4( oƣqCؗH ֐F.vU$G..1X6 $[pdN^At`C1#ܒ[VX2|&W7Zn c~ȣ0&Cb)ą9eQ2 -FfJxDC}:gԑqW`g26[)r+RZ_Ќvm4S-~^K(+u ا4'0iEz-.\7RV4'M Zlp@X@a{{>z`oY[Џ7A6g;<#kWCƕ5Xa#7e-ScH;O.n@hf~ʕtmFeﷴjXH )TteWKR-f+JQ/!{'A^z ;NdaZQ>u}Ӻy[zZcV蛍na-?][ӣ8Mh' HLy0ߝ khyUajU`ԩPT+!Fw3>D9?_(1T9\׵J!C;:1}s$ogx?YaO`2WFt,ۼf?yWò2Ҙ3ekA3h]F_@pXs`Ѕ7O"řx?h E娤4m:&cۆm6|#gݣL.G|k'ZgDS "X0'|%;Gsw>)Py4ꡍwt\ g.sIdMuaN@J$ vqQKTK PuvNRzt0)|ӌCUI\%1ЈåѨUkҺ^ J%TeXл ;le 18c oջ6>z-bQfk-uнIfS6M|n+1%˻ =C"@j.woS\u:!Hi({z?-\?GK[KR5± uY'"Z%u1 x-d~"Tv6"E *7ܦt#ɪDn ANR!+Nd.0'sRm+F5kQd>I2v~DS L޿26BxuW=0ne)060?+M6w(@Q!G1!ʛL=f1܀3*=Bl e{0Nպ~pͽ<%͡tZt/E}3O\Uޥ0dTx$#B#1->i le\=duAo ɬ͝Co}h-\c3wh-G\>+svZe9\˚] ӗCla_7rtl ָGJRwd=1,?@Y{˧;fci V/!㳈bbw2A(c^2"ϰP`4D ҈ 0}y#6Ú $F9FK`Ÿ Y{ҮϡI*u@T[ ɂT),7yҎ|f &0إ')\PHyq4fO(.:kU29e3ط'cb^b73~r 6u"k-BТӇh׉C]@/j)NQk}9)!rQf GHsp/Phɐ^`"oI!J5#^h,A+7sM'>YƟ#z„w{3pW~I*a H4{*SA*śp|o;ϫ~&VH ҥ~X!_v x86dOxc^$OʋR ;W%\'(oԾBNU ڏcHkز!RjuC$3޽@xXź+Xnlc1Pz"&rP۹ܓd8 #/Nz"E7==_$qW4κ7 qS/ĺ2ȹ (7b,!lPLҏ{ ^q>DiM4͟ΦlFwFܐ{[;fm0(XV .-ΔH5]X8/rV:g9Kb4 7/&r^TMi[bV( ؼ+; .Ht/IKXdTDN@~&#4M+4lI}֞@g <u z D#q}FɼL8%]:>M9`67 F G,۲О9bD ޿ίLgkPߕgS.]+sH!+L ֘::fNXvk߈<`%cmPt¥I1˻oa/b>ZC^_X"Biz:Sb.i=WhC)"20< 2lwu8?G Q u5NN:i6YlY 4}; 2o!AB\v.AE%U&s҃h- 60HCSpK(̊jr70ctm:x}eC\0,]zo4Dj2DR$ޤąaiޤUh/ ob/l$ZDIU ,*Zu#geŒ|8AL8Ӧe%(Ҹ~hWѮlv2>k M_S=_ܼ3LbWGLlj>ߴ7oMP.GqDJy]*!1-t4Q\a]Ǟ{"nT"!㫓iv."8>k5=0\҂Me!m` `[`TpB^zһ}b8A8WQg22?)6${u2W:jݏ?7}qT.髹*)2 ų;z-dci9Q+*^/*TW^} ^LbP>o\][2sCnFdD.Ի wsSz8uC.j~aْ*E4i\Lͱ.:2߻"bD)2>UXXG$Q%Y .Pf?P@ۜ.p KCˉWB{I6-T 5|oqXvrw;LX.m"ڵp=ueS-u/қHx|+uuK ;vLFoDj4~0?,[­:[V RUGPT i/pm].88!B*s#":\:mXfM"?"`lO[}d,P삅5Fg7 Gbx6f`ԝ8KfTulS&7M7U5 >x;f)c$Qcr} )1!r}W*q 9sMSgzxYUU4*C@nxmvYJhHs%=ydȾs梭cH{*,p * l=Y2O7k(#]URD{?'eG;^_:)򊥄_oW+S`v94'u^犥H PQJ46{uu*mxoJ/򮤌bV|y4z}(7ڽy"HAl1%2Hk+yGI!XPoMLC7~-W@or9myvz3oH}JDxif6xgv&܁)m*f0G!oC&tgzL"qeQ& a.yD GlTJhoN,tDc|yaClT wH5~`Y?ktAMk%>%Vټ.H$~_"XlMorV{ =RlsBª-A `)%9Ѿ(=?r7! җX\l ?z-E3gR?H* d7G!ON-p>A0e^WAfn J}7m|aW6x//ܳ2j!QKqyBXRHĮ\&㥝jM*Fd4wGc00;,NYC(\!x < v-eRld vT.1\-msf騰К]pO?f u]x ,ChǬp_̋f3pzgE*^XU=Z`NDB6'rّݱ[a]R0xQd"h%6wG ȸGXh+j;nW^59v52OS(m/9?D W)7(FqB;séX:psrJ|m/4bdSV҅G_*j) nKK2?o/[!H"k5#:o;X@è$Dž;kTq_DEK}jrz1@Îґ$T0'5e|)[˽LF*hF#ac=f 8a~z\XtO@4kg/PXXAgDSFXbkfMޟw*gN|?"pBof&XͰIZ-|϶ Ђ&pR@9RP -ؙ`Xq3 =SP9or`-e?ȱߴVT^'A 5TiFl\BIaɩL:ĤWn 5*e<]]z%G-lC#XiݙY/Hzi>(nrs#.nmޘ$\"p2EaBd;|)PD:3=k5'@MqQ둹XnO`#)9`/#i :E_]sAr@oyܩ\E% #8i m%N4Z{'{&e{c"`hN- NtWhcaXL@uܒn[g@j hv#u0X$н((p!~Qtgpar oȶ&0`40ҹa2u5l!-RdCtr4pu%: ep;[](`?5q'1 prEV}H/_ kLPSD +R\/vcA,Џ+8K nɉ##'ϪPHxg)6Y|̚QJ?󧞯vM6OvKzqd? ЫZT;L|.6%5=%J[GJ("Ή5<%P7Dv(O;B+Üo$N?A,ѐ֏YKzGrfXX9gQa`Ua4vuVͯ ̫Dy߯fڗō"Xa";G,mdC)ygj5 ۏa;i@%ns|[2ã$>,$kQ$:'R*iS Rvy\)*"Ǔ&4#2.H_l@EMEAyuUS1flZ*r뀭5KUK5k8QV'+V_asL77vvC;L`j|MK0AlMnː(A Fxz|4֯:R75y*Hتkgɢ;E48QC֌f=G*1>HJT^)fSQDqZ˱;!ݷ [K_Ҡ}MHTNKyԏR(#mNJFHwӛnp!EN%R;r<<)¿0 ,!"Bv@&+~>ϿCav:foҴeU(dβQb1#%;͌1FJt䋳j#s |px.  H3~NVOWI2~`KU[K*tz>RڢK[fr D%-!҅5` ʮm0!MьQ|9lK"KCs v?C 暔qtUqEsrv 7]RO i(+Q#vDMA0U>%Rj:I^MnwXCSV T \YMVαg:gYEb,Ѭ^((*!/4bv.U?Mnwz-ƾ\Yp|9T)+ق͚`Eث (}FCš04~߃9ypa,b qsvƓw{¿L׫6^` [B1!!: x-`K!{eRli}~e݄Q@^HuQUqS iC-3.xb"%AkVC,+?]<BtwkD: u mjK3l,8An/~wҵX?Tg }a sx̝m\˩)1l+2iؖ3\_RTd@25핰zƯ;>x~̙iƕTQϜȹߤ:+N XYrnɏCs|@3{ymսΙ.*b/3!(O~R |O\mU[K~+6P=@J}ŰUkD!U ^S n f-n;~! S'?U:p1ݖ:23t < v~Jg1?uŸC7uo}|`ijW(c:ɂ.[>y;a;MVo TM{WȤ^u-xI-w罹7E F OhDX?u h^ӱG؋}S.{G-Ķ)Z#Rƾ#fl $;B0'~҅­oKnÑO~h[3l,^+YG@6m-x;:nUUMA0`j0dA/}4U^J%t%Oڛ=CElׅ{g >۸գC'>1]K`pC]u)KB)88q >"7ިVޱ WF/G1DtI"^i]Qy^_m`rc}S~YY+HO$^S4^f.<{Eb?*.a`H؛ ?i^Kw_qPӰTKrbnjxK9W_3XZ(9jf<6Ǫ}"oNLvwW˃Ío mo X6JaE +ui6yF9۔}׽&3{i[[>UShm,|aK=d;BY;\r{F[9-B-U 5-f&s`A΢3ӄ2TD>!3opQJKk_/ B/M/kq*:愈h8ֆYbyOdl=ː+j8(Y:Cȴ~NNV(7Scqa `җ)Ĥ^70 EE)}&Qy%+(}Go G\{tiJr /92z2a*ԌW0!sPRzKx`!՜,;P}1p| KE]}2ڝAq'銓jsNV:%DehKa(\`_:`PE 6h BI}*aa!ik/n;^ _}4r&q⮨FAzbpHQ+i񮂭ё 'ƣ}A3;'!Ҕִ֥P T{__j[+y>Y3h2+?ϳ][)c`句$6$ 8gwi S#e1@?OKtq~Z,]'uH)􉼤ZBkmEQ$|Ψz):]&}jW1;2hr >u^Д"O.W|D-Gք'9K_CP=rPBi_ Eczx"[4GF҂/"H<㉑L$|3WBm]p!+QT#ǜn`J* kTynQt{\/J/'CSN(n\ %^t D6i(g.U:J);q.pg##YO w Feje?jSLgfdS{sEN[?a џW8=2 %jf2aqUdPkRrͅXcN;L8 Hf#A-M\s ?\r8d%f#jm4<3H6;b !vi;f mܻ,F#. ;;waصq|&a0[ݮ[dxA5j ryH k,Gn3^nG–0!@Ӯ*:J‹ ^ڗʺuq */@EƬ!A>Ͽr^ $\R1i6 3CWV1TkA,: B^993H)p̩AGLW"T7GђJf|XgQ)`c-< n-8=n3(MZ[@Y;O8+NSq\*y&&`}zنzE6M5ߥ,4zGq+AT:?pė%c 7B/%:P5X@Z_DHv uBE6#D}+9hdɣ0r"3XS k+o 3ju]$1[+!@_iwO#1䟽.YC g+KZʆW:]nʮ^ۥ'j'_Tr_QJ@4S+aWvc;C[ fOTkP߻k,fN-ϞAZ 7.sne&tDwi]Lg9 @W68.ܫmhʷ%KtHCԂbLE&+ sƌ=~ y x~PtDU Nϖ9e[~|=~ޚYy"uͫf{1/_O_5kN.w6aWj |7,kjz^8NJ 5hObtXkaL"kꟑZTYvj=9 ONoڵW6Xh805.zaj*r, %bf( o@}`b.o. t,ҦVMwT5ը ea36o…W +u`F3i:ضx\[B'ǜ_0S1D)x|GCu850vlQj#P*W=UxYpc\V\9Dēw Ul(ұ^·*^;J`J9HP#YYa-a0kNт1X#e)yeyye ckx1Z>U[Ir=U-`٫ y)eQt&ILk_{~ڗkV8T-i"53byGw('ZZtQD8eXKv$ï<8j:(,hTa^oB~ƯN}S-s DtS_twB&:\y:  kf[3o+A5)H@#5XW 4_[L g#*[b*:\;cP_ldڙ\2AsR0[ 2ww>IAtR}07=ɸP ;6޹]74M2RA/%m&SB*m-`6UNO()2~u25Tf/zk/S-ORcq޵/102 m-qHq+o]mݰ-;V(Ӡ&ԳSZ6$i4h ܰԒLtL7J#@̡ya=nZWJ^ 2ONKޮӆi#xhuo7 Ke3&'3֌c;RУ0nZZ B`HuCq| 'GM40f@0Y^Љ>S/G@ s ae `]+=0064SϊWtyCSJv6"dzSi*{q!^AIQQSiwgu*eB"#зKZ)5bY*m>,y9m zj}j7}U^ ,b;7⇌uKe6]T bO<'ʨV+i@K?kZG/҆3zwDW˽h.W٢q7 N{ÉEYLi%%0x>Zf>ȺM*pe?pj%@f07|& V-}+ e2>t^0l܆AvA^t\Fx׀ހEu ȒE t FBp`X #g9kw'fYF3U'=;% ˫tTk9!Z[EdΨqȳW=`4M޷9&}:b_Ƌ _x/i;Z&Q'ò{vXTzw7/ArҲԟ,MMm>DqƆ mw}+ ZZ6_yZmjPME.BÐѫYOVw/>Yw<et{.Onۂ TVfU-)e\ʐ4ju:6 ǖޑ s hY&bKģ&<Ⱦd(ә.:# RE#Cg C=b`2pݩ;"tx25P]BVSu{QNRL|TL-e!mY̕20^^\q rƵuPmL H2n'ɦ]28 &1aם2Q6`O 7KMJ;t)m\,QZ A}!bt@6OO`gGW1 1'"itVYE=7aA~qƁ}ԘgmVёrU욅49f$l +js}_ҚFS^-.Qr6nJN`/O(t=mg=ke`ǁefӾ#hIxYc/e;en&},] ~<84N-̶@4a>wgJ'^ygjNuJ< QkE]'}+#]-X .}W+,_f1mi tLĊgV ;VyeEiAkZ.CEGԏ ̣jzOVV$;dT4s a]nOt>\S`tkФٺt`E" 1a׫->>dÊG5ԔŎ:vq /j ס/u,[HI~")}S `~T+C)CJ52pc)Dg"G7||~fU tUӖp!ʋ'+3M^K?vmQ•VVn~`8H!O;O.ڻ&1%)[S^(ڭ!f!v7y2FbJcf݉ b_dW!\(c޹!u/1Ik]c} ً8,&؉ 5;%M8n(G2tV5IM.ZZjx>!ħI-d?7 ҐY|;"0<;[m #lGvO/X妪~8143lC䢛$y9Xc]ӓ!1 3>aCQiW[~ŤU %G2};4 7gr 'UitᚓN@F6?}O0wr[cr]K숺:/sDn8rJT=î^j Z $yRx`7B'l򞑴|Yy=Y \|zcBi ex+]XVhjVJv]N}sq(*Ԋus] iXT{uoGqQNOU+Q(̐\}(xpX8;>){Z1 [pFс@L;EܷYPjJfX wwBi :ظ5~[ v ՗\B c-"9sXW/4Y*-OFf3OoBjB}FetL%ylbRQCQ"Mb[5ڗ!{77 縛mw@\KI'7g`^CT5CvL/)09b4>%#0ӽn~]q N÷B4 VO'zM@[cْ!,B+>rggFG&KPצ1!0w.Ԏ> kWg~ .qiIEl&"kC) LYYs/A L@t}bi|I"k\% jqJͯE!6]kwu{ޡw+P讅yfw4ajP!fpz1# aGKwLEKU,$`5\-g` BF\dwsԊP4:,K+0ָ-]']L7#rr٧xb ~` *!q[gl8XL1&+8(Hvԣ ~yWO:mvTGWhZ`Xօ[:P룲=&v \'v%V=DZ4gV-"ՋXԑ]ցNrL*#oGigP M1?=h:Ak4<`~羶8­#bMJBQ 2Y-u!Ғml8R Z b#܏S`QkKiw+ 0 1CXջ SWADЏI"RHj2aA鸑Y9v랧!GA$[\'σۛ u%c(OЯK='Rx09:?ZɬKN@]soQQg;pU>įT!2›+oIA UEZ.u yҫŬ{ԩ>w$J7̬-DjeZ%A'H[QV p >QlZMo*Z'r+p)kt%RE9 j*L؃ݡ $&ΞL$>BC7zNRf潈r;rm%*]6n9=:qeݝi0H턗%S^8c9Qװ|sraTc ?6S1*24*SE8iك$<`I!"rVfōQXNB̝Z$l;`Tܒ)@t9 Y5,(u"3 fHtqCgO.oQZ429'A>L 7:ߋB؈ xndh=! T KKe  <hi8atdŠq }pݲ& &;UE˜;r Sgo#U\vLƣ<DžQrI?+hƈB ڭI!oǾXxvᑉ!&Ҿ^lwݏjF {FcY|%fzWlݍ_G-0vD\z 1IXe= TJ$Aε!h$k:vX\!d2\ϫosNП2EE MIP]?9s@v\xdn<]pyn;>nSk˝I h 2Gw 99(/"b"^nƤ̣E&='g{`IPp F^ \nm+UeކI/>✹żbҗPX=! %Dsv!9HNrqP6gd$1q(:# 5\~՜RdSHX1IKvWz|%x7oj(a{pQ#OjJGߍB'וӧF]•y"P+-Y 3 {Z,}ɢ$[eƤn$f*0؅(^Θ.La8[ ~y0Lk{H_K(CIѾV.T&=3R32+'`Eݎ$tb M/Yj_~i#N}e¦0;BuR|v4eg8*@GK>G{e ;=(( <ޒX[jzi$sīpō`U) OD$'(gTYmØE\"*#T%e7= wTL# '=&+E6i@>*"`M6MCntr01ˁXq_}W b\HEc( ΄JIukۻsJ*i2өJ9Og~Ig]Ag!1(Te$)K)yXt*& Mkq)21B7Uv% F὇O%7vo2˥Kj0}>l-A4G$*+p)zCHº!_$: S}zMG3*9oʎĹ`@^CLRh!T|4c76 QL$?-Cjdt FN1C+YgoA|Br5c$~)f:SyרWD&= %;p OEjRE(˛᡺Os19Z=u`;|4JvG ]&M sͱ6BQlİ P_WQ ֑+ քvY"u$6%&{$Wkl%E4 4M_ġ|%RHKN6dfvJg6f P?>@Lrz\ʚ\mB}kYk&oX.o ntX'&^;[t7J+M פc.L8mǚY9HF(ެl#?2M#@!!kP;YhHǶeŢy\qHxuоhL~i92l~uEX9L/jX goST?*?n!c3RtbMd]n_{U3%Ѕc=ΥjK kɢ#nW1:Ҟ b_JE::ɠYȸܟ](l}{{9h /F̥4kqSݓVBwNyQfmb_wM`7oWvʪxN)O<ѫ/6qJ+:iڥw|BIi F߾JiśH6::ͰMZRΤ5Mi Sh+4HQͱfx^#pWHfi}睽g3'7> xlՁ]rc#u1ah'?Vv`LzѩFuK==@uf|]T>ýDN7|@ ѮS:z`ZY'IިLSrTg]pz L :Cڂ k j)ef~Y?=}4]?_\n[Me%SG?ӒLȵ̆^*Q%^Y%5/{Dwk؞;$kXK):dJФZ@ ߈ʖM1FH tx^t %GȆ#4bAu@#Upґ+ɀ t]ݝ)V~?>1{B\;N.?+(gӴ=ͶmYAKܷ$қ †ѪbyJ'mZR fT%+ҵNnTl; DF.uW}l$8RZAi҄@:A& ^IR`҄hBx Y ^p#(Ɠ=CK)"auI,i !ǡ2ΫuSbaUr?2WÀRxDuĞuGR\$,hV9AjGLj@&呋]UeH6\Z]j]8 QeZQ}}rQ?EQ_30˭ĕ޽fH{4rÖa=)1 cȻ D@t:VCzAuDg#ć#ytz, +Ph[&Z 5}ȅ:ɂJr{GnKiM΄:T6'"P]`xΞQjퟡZpɩӺ ԛ g* w!\|ъ^ WʽF8CAD"I `P7鸻WHp3/ؿfpByo*rUKw0Tzt nٸ%Z%:Miׯ2g$|5Qr`1^6b $4xQ|RO cjfDY𽲫B!94( s΂_36H0Eyo\ evy)ۮ8ڑ=נ?r1G(rJ/rI {Ԯxh568b.@I32RDV{b24*4kߐܭdB~ 6ڑuI*䬣e!f)E3?(rQLtj $ű= @'JhgXS LJ<^dcE ~b4g2Q2qST~K@ 35`)bѝ㿱joq9~O9iwlw2kLGk</vA4Y%TjQSo L~5"q3̞/Kl@1o>nGKyqݝ#8ש~@;#hN2=d%`}E E4q B> [xQ>D\O++M 萸p=(1Ͽ )ժ8cALGХ4NխyjL'E?A7_v/Wi1w(;YN7Ǣ8 !'BJi>r&L#&,v?#Y1Fz~IH@s`kF{BՂ3cbn:BW7GzjY@ 3ʃѮhm2"?Et@P4h:UDq4m!LVb`CބV9LKq0UFzHc'!V:,mkx+$MWܕE8yOAiJ03[$9}ђ&8to{2;NkYR ĆY$0qfGjuSNQ;!L",F4(eXhn&w]fQ#Kc)%CfyerAN@*#R.?f=jƻܘ へ@ΐx TKul[w}v4ULGrc8NM=9vj}uxWҶFO픖Z&Ly]5YSlk"=2?y%ζ m:XZ;D7)4"kۋrqe{FkkCfW";>yђ!"m[>"vׇ]ʁZE2 YzV(o *4{gkm6I;((VQz.x*@E#WcrjsF"( ! [B..S9G3r` z,hig.Ai'aRf-y.Z9K#x8/C뼇y84w eѩ?qm0cmRBmOKʯ7F6;\Q2q}J?ޱ0"J *P֮W59)bVD y6_|?H\4<1YqC?\יoϣ1ԯf7jCp&'e_}8)NHw!q$Df/ٍ0`_|]'Ge^ra/ WH|"\uWBTT\5 óh@#ذpz:BLӑ#,Zz!b]z)DZ{r(yQ%^զ ؞9|򖇘 .AD~yumj:^GʹӫX(0NbCڰΙ̦?;\Nڋb4ܴ@s&+*Pz!xC;$3y9^{/{yKg4]D!xw*xadgZˎƮTPGlJus+y O %'Ζ⧕Ii(Z1:?. F%_F*A{Fe9^ [9|cL:imw@j zY8]'LFs {^6!!+X׵4GY{#F̼R1άPbJ+bPj20l,NΜzcg!Dv\zTM`=Ródf g?<ɔ<"Yftۢ|0D0F]h`#"F(sDٛ98ІDS5I`x>JNp(Ȥ8'2[@aL{;ݠ F,m$U!6hua{F8InOg(k|=b,/8"^ZOvQڤ~﫬Cv\ڔo+ (m-oiBl@L|]moհvEL]`||f6z,ݜM wHJSyzpKa#_%ֈ_ )-u'uW!ij$?wם"RhɋbXR\}5tYжUacThqAY&uR`$b?v}qH@< KRlDwPp!bi˃Z[/~!t-^W%S "4OU)]w0S(؞x9^O?%wsMk%WPc =~1+-۪iNo_&6Ѯ~ʗt~5&(QG3͆X>UFԪ@tlF%{7qV⵨ƝA,rufI(=cߍCN_BDT^V$-`o܆=F-!<̛[5W_w'A5^KC4iC|OCbrTfʎ ԃ37kpc{ T"3ucB4U E *Zy۱QDwj Vz>Ƒt䖭/_G gN3z08<^z7JuL8l8kf qM+p{BTA 7d9\zB.#u7nT >yQSZ=a^}_R3|;=]Khg3~> }]炝\cTfH2n\#Z ZD&J h7m7J^<ׇ&m{BА0Oɑ#Pf+u^AۚealC&^u m.T.ߢI= rv% Ue4i%1 3X >Tÿc{ +k)JI"F2|2֋@C_oG{uOBWF|&^R*Q@FN4K'oZacN 6L6 HV NU ZvDV8l/. 4lWd7Êv*^(IGx fr/|-2ןK{:ϻSّޖuQTCi_-h9W}w%1&| WQrve2gYFdˮ1A#꿑KkE"$)'9 |uO$]kޡ)lƛ\_pXbcZY5qۀuv"LX| 9hP鞤}44T@(wsiVFUt{6&Y5*>F_Ͷ ̽qme1>o߳8wS"ug>kPFA#6@ˉs x8 1o8X&v(8tGXڼ`  va]@F<:al1nTTmFG=փݸR#c8aP̆SI&<K`!0t _Cr+ugwK"/.d/E6I[vatգfW!'Su@9%8'͓/2 GYp;VG9 vFh5Ԃ5KJqs&JEz2̳@p<䔺': ӶjOAbO@Ⱥa*IlPa^ Bi3xOL@'SQ^Яްe1^,&t'%AQbe~㸙PMYw)@BO34|ۖ[G`$|M5#4{4RDtX9v8d-a2V<ΐ:3sD,O}Oٌ᳞ ClS@Р}Tire5O98ϵs+zvj#& PӂsBddf ]dv'̌m1yZS mf&ep>U#]D@ifiT)c|<΍ٱW!Nۼ*ô+5!*ӓ>*H[|͓qa{uj!17xm%RQj>,L@\4?9K/Ѡ 0ŖhzTUafd%oq}%V_@KyZ᝞bGaK}j Rw%cS!a^*ƪu7ࢉ/-Seko G.3cA#mz7 ?EK`gsleUj4bocT+^>i Ks:3Fxһ,=m쏕eB[9N$:5= WźqbAZDb?󢏊G0t~)!c"jki2=, }@̺7D7 OM4ƣhωVcEd",j? j* K=%ӛ\eEVKj ,4X1tT6'OkrUoڇfu4=!7鉎S'm]#l%Z.M-s.&i_r< w͘n*Lq.VSv̏l=?ow381x[ub^VaIvxb5`]~ك. Zک4n;5nϘ=xmV'N= ρ\Epf KMG[A'iV9UXsR}z#Y|d4,HS{(xG W'tktLƊL$kdlE| IyYN#1k"R)ZrD e_?|ia*+MQے`ۈ. #l]&H?$R ᎘m .rHv;,=)de3/[TP{P|nעkd_.ISx9om *3A/'3׌Z p`ge!@{jqC6tY9 ۞s=;) 50ynTF[қ$MPs:>\bvd{kԺ\gv$XD#pEn[?WE*tR+5T a 2{jWI[o*pQf'YÓT ;%a@PzOov>}_v>,rO1>,}V%"wWV16=a,t:V Y<prMP˴Pe4+y7܅ iT5jNjDlSG{j'ObAP{@?>6W]F/ad%x,9\4Q25a4ۿS KdL[h)p8%g|T B'`eUCusmT Y*)n"nD0Nփ4!6Hss#f.fsh3`ʓuǺREr`'_ :%p {:!saƌ `Β"ܬ¡H8ѐy_ w&$ꫨWe{0}κ[jߞû"IqWPI9o^.粑2am?+WOP3HYRG>0;VZZMr 4&ƗD(ڧRs\_-_  ВJ%I̭*3*XV":< LzP_DO 0G>L;vOvm* T6x ٞ+0 bݠ9_8lSW(yK-@ X\tVvYl f)Ga(4hԜ^>ܸ-QIU|]ηL,#G,S`ZĐdM#D*T&$qR Z/_20F Q.Ē$bR"'+ ld@mJFA؝w\}9ߓޛ,˿I7($ |HStnop|ݤWyAZ+SJ~9["󐿳nGdԷ֎~~,DLˌ4VG2M!O[z [t)v-xԟ:5 mvk\ yJk}˕­p1|a fi&B@~LIs]hn긠U>ә7T-aH%?HQ>73gx;`/e|0pc?Db9`s?L l'y5N3t,B f_B}(Q,&ϩ1OR e]GAjr4οTUҔ\}e};[A[X3iMb(NM;nY0l<80Avc)(QIvñ\FuxL1&ė5}NhYE%8w"JY-s! >SYvWh^\!.YԕI*sJqdedX[׾\orJ/ǷAM鞪2H*3!!Ek;_@j$N!@LR: >R(мOo';gP!R&)zff^'x`.Y`/-Jj|6l/k|}S}5 L_!j9zH?2Yu/,bcAtQ}ԘUϧ=RPtϳY6lqA-Ȁ&)MU;se97( #EF1[=^Լ:AY"W&4:x62vC6s&cNabEo"w8Pnv'ҕ*^ٛASNz%0jJHxB5pTD&6qV0;DЋn۔pb5udĺۍIZrɊ㪀 S|Ys -2)c p ,M V` Whɼ 7*w|DGsb-[c[BD &7w+}Q2knP77ܙz<3aEN:%)Yi*bv,zŁ0u3#W7;"mmz_} pH(icJ6 8tqfjg:a81h{BQdͱJzԄ2wd@R{bE یW4~C2dq]Gl  *g[p|鷗Z31όl®;/A+i-LΣ<>%-X;` cgYBJ)Bf,.^6Czق2W9oUJuо:Loa>Wn9ļ+%8ȓR$nN)_綞_].g{3@xJgnWXXz\3[RJ@z2GϿ tٚi1q F8S>HIɚpq%UEd#[~ %!'XAtE)< b1T7wXG =$d [>"=ĵ|X~qxkbs*sȲ>'jgYCμԂ dvJ8,8%[tSz9}}5+ۗSI;@l,4 Cz$\6øMtJS 03t@NF,"An 6}G=2GʚjL;h sK륜&IҜJer7zEqXNP+w@ĢO/:zڇ~.l~v5PX)YUs@A|Φ!ILA,o@J*Uа< !ї ^t/x!E69p^BeKu6+C-w^ `4%{w`9̗ ҭRTr1Lm*5h8/1 FOǨN=KO] -<(Ɲ[,-" z}inBQ3Þ\[5̯WH+ eE]lP~iV:꽭 q<_qX!P;N G\#N<0+U<5 V=} pBI B֏VNTьxer>3ov{PBGkȿuhQU 9` c]iNȄ*' ?L3_lSA,QVĨs ;(֊s3xЂd+̀} d6aHƽEH*?vFekGޙ'*;'+333;HQT,.lh)b<: "^1gʝxD9~2>YI0$^e'tBPN\#-107F55oh=UӬkAaBzctY>=un9p{`Gt.ag}i9z^Y.74}|kٗ$V>Z,hys*LD4R%97u_Sdijm tk$WՅ0u~3`7;$@w<|"^K ]:t4,=ܞk'VZ_Tէzk%&js?< \D(R J2_7x%8:]Xo5fb%|;FҎ<))r\yҾfChoh=hM?0T 568hlf"qk$M8yvy;5h*[쥿K6Ơ t; | M"E)5pNp94`M??3Z/ٿM!$([!8P!|H76' N3BkQt,eoN;~4:Bx{9:z{\&vg6ܖa?,PCa8QVI P~|-*"`vؿWhbh36WXRx%!gLȩn$+xddK+hL(jBVxrG+4Kki߇l$@ dQ <0R 6 o$Hm+iR)}<4 0%sG0d5 4..'~&?+5P KR~SJRyFpіu, ֙l{_6e0;kNۯ vQl8V6n4UAd=f&CW0Ck Vv6e$m-txd $w=90 niD\eo/1@2A*;لecyD&qlHx7ifshQBwr.4;AمКbH3WS(l0 S<]pl!h.PoF]ۉz'rxL=9ߢ`ֈS~_䮩\R/ d?ӹv{< tw5ݪM`ZZ"РǍ9+pStNbOy`/' ls% R耤cvn}lUF%?ږZ!D4]2)G~NZ9G.6+3 a^#3gΤb“oq4G}ř)@"J`#aIvҤ;RLrRGYV6GV?{GyG<ԞO3;q0.Җuu4M,6 o6\J2Ca)$@u w'|M. ٜJ6f+l XI 7'D:+S6FܻB8|Zgͼgw~T]kddճv͂7q5|Ƀ3e-8EjQ{yW3/ AD[Ʋl.Ʀlj-_d7< j1y֍1R5:7ّy2L& ]كD)k,OV>׾A6܃cHfIx2v)H&g:8D+s8O]ǞAI:0FVj4PЉ]X#f6(5~-܌>zBCɒ 4٘%1 0`10-\ +b^#=y1d3XՉYq%!Bw=ˈu6W)h)~5NZ?3JjU]YP-2=Iۚ>hGગ'VZ]\1/ADDJ;?F m2N9/kّw%A!l^xPsi!YWR~emB aD6A]רV _Xlc밍!H enwS b)oK;QYcžK:rjN.+/EW%.s(E}Plն/L X™!wo1R߅v-?.r Fc" КĒUڈ$zQVDȓG%٘y%a_~(&>BH&총' [F|`L.V\rbU>LZMsJ\ܽz(Vj]-]tc—3=qF-Vb, D*iTCѻmEE6(|JG|KW0tpa\S''L|qTM$wyy\k~IZ!,{7Y30DRH-(`fTo9׎q0)Hѧ? ~,s XyFߨTAe6 k*P;*Mύu,5?h ȋ,/Lnz=.h7[]Duf"Aze(v ̃.jC-NW zJctCXz5H!EX #q7G˕\< Qchjid. ?)hTnoOp-D$heUh|G- -)6(j1fb2dmJo\"3aA7J _Y@1?J ge|&4{C]S7\e$8oV0xؤYy1+rX#ŠJ#;^}D#,Y$|o·cD975 *G"OU[Xwekl嬿yecЦ$^ +셯]M}amy$0ݚFhMIx_6 Rp<z `R261y$့]m-g7{,8las@m| fM%]NWq]>+Kz?VrN_3oGV*ёK2/*!وy!lI48̊ͨRHhk\gٖaSk4.(ؿ2w~7GKHbNl]"IZ@LJ|Pe5 u@g$nI}C T:v0hYF54]S@ʤ*0LLe5gP@s:IFPO[úZ[Z#O??>6xѨ[hTPKi1H-\AZ40ӦK3 P3OЗGѱSkz3PoޖZѯ|Kd{Ddg%ADܷzv(Kȏ̗N }s-H[ݑ 51>n2! PNӶ2P:lzM) ~' el(=_~;+`+ry(i;n# gGCMҀ̳OZm0+68W]C0$.KS "T.idbCT^$f4]%&x.Ĺ{{7r@5Ǜ(f3-5kY+pSL`>'4ƯY3?Kߨ~Xħy晷.]ceiMxo}~båScq6m\XK+%Q NiKṭ.jw{Ph 뿭{9-RkՓ #Cq䭕꺗}In(1|Hr*wDaA yա ۛfihe٫hI($}Z4(ֶr$dS F o`)ҶKcR=~#|Q|ۖiٞ`Ud#5|⸏A籛:ˤk9 [MFq @]ۡex,{;x(Б KRI(v5-i.^LR{l8`EXKy_UM⧙FT,Ob^@޺:u%VeՌT\ep9^Ssh:R3мKka4o-(jHtf%~}޳(PI">'N%~\2]%ϠURM1RD*Nyݹ1SU J@* i,!s߹K["6z3~[AwEM}UOBEjл(ÎS@Ky@+0od-FC#jXT{gp^&'A$[h|&D}n|5gEgᗮtluk3 uvc?fhC 7#o+ `%"y\+  eG;;:%ozBSfkpk&44G@ǖvRK NJ;+$Ճ#kdжU^^E}|xꇖ $s#W@:}M E';`ƑX2r56K1k9m%P6gmF_ eYէ9@[^*{,vgAޞh|ŏ?pҒ5%rp*$" À+,=N,Azbe[h-Ûǵ4넉PıDr@!}L PjF쿤e3Txn^LpWԖmV4I=Q2ŰV#xZ_t]-{ M1Jz?Tpkc񭑽鲷w`ajlFfYoÎqޡh:~Ŏΰ("u.l-7η9ҩAIu{ ŔQzh U_ϩ<&*9el㣵 \KiXƱ7 Rd|B Η6b& -2/؉ ˇVǍ(EBP/sAUoʶnzlXY+H,a﬿CVO t Ԏ@a/Z|m˱hCLֺhn#psT|tFͱ]MShwlGEȲ[@UQe<|Tc0ʾYkX1Dm1pf5؍bnÌjVM59p=N{[=# ::-VV@5,~f["c? ܉ڹ̀ 4A4Nm1ʎtRἐMKpT  5[H EÀ8KN}1QkSYi\kxbj%0I0Z/pO>@-!W;ǒlQlsEZMjF 96,2Bί֩ B+N)'NxCMvDlzdu>/nh-3~|;i_{?WNejq l^8-FOЩwJ6SY_RS84^<5ػIi _: Ԭ61䞲r/N;N#u&C_ %u+,w^c>O#p).!'#:B}RSOUBf>;+-q;zJf&F{_,[j_XC3·Lj; yjc^M^|c1>e#+]1Fw}o(Z߸"p't}YUVטM1wQ{'`PK>9DI5m_HgOV<2u$r# QE]dg"SK cauhx䝚%$b.o}^4REɺr_5EVE0c ŁxћS7(qgowM/VudhXv.Qq`*0Nui}`ق R Mf0c/!a9dӁa"e+,|`X>RM8bhIǕ_Ȟ\FM61SxUp1U HP:u(,jg2Tp0D{R==Gy^he-G)qciy1ee0Lm,1

    2;n^{a9sه])J*{OpsDǴUj."ކڬRa"P%ߙm\vK=9|fc9 *d}B R1߲99qE%cO8负˒ 2tp"ήw~u5gx?}ȶ1A =2ĩhR  K-UoZݱK)a\Ws:oΐ FY}Sf7p YwFr @Is>ލ YnoiT,J} }@O8jEŸ?[^D3-JJ'[.uR= mAoR[۝6$OkŤG[W Vn)͆R@Bc:=hUw"J""FJ?r]MՉ^>t#nmY A<H{Nw~ mM]5 #1hthm(QE pa  .W,a\ToB0BU9M1hՀYb̳zov=P{4Ґ5>PCA-)]|Q`XQX 0E`ڦ􆍓zTu:xS0X?Ȉ*U5W:ج*aV>h13 gc?+;PW*!N NxU7DA5 >Qukϊ5iW+rJ2|5 Jy*L/W0.B`oCnI+bܲN*ًiZE~.FA {y A0^) E[_=HoWѪ>E-h0RpsDB!&j|?tY3H8|S;ap!*a?L տMl|ZOU Гdb<,؋A⺾82R^Lpҋf,Be*;/R|񤔸7 ++-;oadB@pĔ0Xl?*m\cV+՝V}pw)"rθYVƣ=f=a7{T~ea-#F--U&،w2~5~"r<7.U۩>1UGaЃ[tefT$*~ H -ܥԐduLt9ݰ"@@.#p2l~JF9zz,zv.ȷq(O;IboTמ JQ;Y?z1|R+ި;xn'-;qgmGeR w!R!w"܍YD9BZ;4^C% G)y/͔W+5ZW{iDo%ֱbF!~w%L`D?{Z)Ť_iڜ˒[~q/ijR+,\>1 G"{(#>&^Rx!,[DX/j"HVNzvP Jyln:Fx%_ztE}.RdmRdžr<4tHisuϾ#ɐ#lSDŽP*\$Jq+[AP.c T>ЖShlkL!\{؎ taD {> ;TW7# ִ{1LV_{5 JJ{x lmEdķV~)n6OZ%4`Mih$iw1(2I׊.uΌ+' "/Ѻ8lB_SkC'" aMI" ),dI`IƯ@zO2ڡwR'b~e_Q[/V@hH8lP/%1ZxjV^2MI9cɂtvjRsSXn9CxI晴/,9G/]_c U:C/qL/O KKdĠ,j/!&x^5uLŻ`5(9ۮ?7-?.Ca)ysx qLZWSYat1=Ef/*JQ&,᩽hdt1V'6,GeSai; W3CU;|*f6ҲXb768$s:ؼP=@j7c ˩l'd1&˂;08A9| #6Sl=3hzod*LBWL-WuzPXIvQZ Khg#о\n*?ȠTcFi@Rβ82< y-%Nmz$.8i6`~F G[76fad6ϐr0p~ nT(`!$5lܭ[rw%✞ Knl]&ʄIq1rz0o);l;QiRZ;tkƂI[C䱵m/|ˎ)>]L.#8ԆhwksA,ԧuk +hT?*h{LChyv|G3Ҹc} oAWSM4/nsT'IJfɂA@Hn5؇KOVÌj8{iEKZ e6ݵȶ` )P]iCm;Th{x+ (`6 kJH̥v|gG6-au䏅}VMA.#]Hy8ky9h !DIr=}eć1R #g4^?Nƃou<&6i(>ujUڴ5s/5ɂEs[Xʊuk`›9b o(GDVԢHe2nD;cCsĹJ/7yˁDw) Sp@X`&V-TΣn#r=$f8RV[mGt#)nŹY ೒q,Q00ځQ)V9 Dhf.V:F/tT`W1ejA %+A|^_g4WJdK5g0vV8"cU*OMި/Q*w+vBJn#`bn#Ȣ^) B6 Z㉲FB|yW&0Dz#t\vؤc'6DBǮ(#ֿ* m7ebs"&Uhg0m7o" kͬO|t`FE`$= Imd ɯ C8}l͊Z+d3P٘{Y9EFK}+~ɢ2=pQL/,h!8{%W|./oG'(B. /{uuRFhi`Lu`޵̗T6F}+1) \~*E5T'!5HmqF ^*#2#@ Ë v/Ur [d,GC|&=GQKxV=zmfMAv(-:( -E6&[O_.};j-@XR%^Ս|:ve_Mզ܏nUn 5;ڤm@d _痏O0 !hXgpE=rqN]ʈFl׶w[{8}A^# ଟJ{ QAG2#D ̉+\HU+:xc'SK 8wTDDohe|vK]q 59xhO!8kM}μ`B:#9 Zi*M Rbr@f&+RT묧g hhGPε@^!>M «È2.ӘU/lP!:l:M/2o8`:@݅ ^y-cYfO2X`{lV D߭ƶr]BGx4S--?xX\a'ƯGM c]$$Ueݑ&@ BQ]oSYjY~$zr_~ ݷ:t4e =@zVeÝ!D4q{qOEFB¯kDz E rF80Гd+-rC?Z8pfpJ X:HJCgԡҧA|T "L!k:ͪޓy$/4JJ0ߐSdƔ<~1|jكA'w⡨1 1':ovu5ڌ+9fɑأ],V 4pm1S fvC ezla!‘tШ׭Qc%.Ӌ%V.4KS*mWiJAT7}aBA}vGQP+`Do[<I ž{X%2 IŐmGQ*Nu+ddm;ɌڅZ}L->ӝO2\$S@R r#|*ء0S>=d&BHRv,w$ֲfz0y.[Dqȱ[f$,I.y\̜2j&*C#@dVjNe3ްLoMq8~gi7wWg&Ti^]+ŁjjCzlr$ͯe2 ^Hd~z! by>+:d8ٷ h'*=G5B*Kf̅(S7f +41{Lt\~|SV LA$#] r?njuJV,2'B@sdˍ4 TggDFCCj12BBFi7m#> f1@FioŐ_aP_?wnkq}ۭۙUn!NV/]Plyw@mK%K٬AUCfk?6]|Q5>>۫HHNc{5sU}TSW쇕1!(JIsa]#OX(|`o&X!܋]FhA h|Jm_c},F[O=}trPYy\58ReɢՔdR>^pԍ8Kٌ7L i++s32Q mTIH$CxȰStu:'zrt(SO|kvd\u hjKedKHSyEKȕ.}WµR?(RmmIO_t.pahKA2R۫QcP4zQ==wUz)^A)&rϴv:-V-bb‘l^3i\ Q脚:(M"Sa 8w互?GB 68 ߍOa>zqJu!1@@LH Ua =$r!-2ck))bErPa7:קC/#npt߅ gI!1A&NmL?,T.)'iRXCWU12AfcHGbG X2ٶ:= NwNkyG(Zu-nK h?|G0hKœ&HWP=_$tyPuA61A4^ir@gZAJ Ζ3et9{c6J5@)_ D1  j솀)]/vZx]}ʱȅ/Ӛlm<ʉǗWkM)6ʺV[@wki9$j^2-QSFoJ[jwͻ0<.SXUlXs#]C &?𙹈#Gw< K?<]x9t5_ɰ]/fId^DI: ɡ_ @F\3FMǂ' ȋn$-q,ZVOt]oLyyPWpO=Fvً% ץI;['aYnLs9ŴJ-9~{8> q/gӦЉ<k=P5ꮣ5VHkŹṟj9wj }HMթ88R%lx.ʐ+*S/#``֣rN]Kn3_ۧA>t6%˺F*C&xށ8Al24iG䝉F6%ˀ?޴z7ӭ2#QG"eKJ178[vC]a E{η8Z]7{[S:aLd.t*, w/~vB~"\!%fp'ep]d:'S$+&yGr1]ʰv"*z)A̸xYXuoKm +ھ'7/:Sԙ@-FSh$p!U] &VM@mxIsxJ@d elLw[|\ K< _5J* G!X|/L)"F(%@.gX.a#͔Wi—hm8A.[m:tCKB羅jhq#wr u& a} QOv 9D>zIZ;t'C2%QPCC* &S -Lj#d^;KsmG}ݶJ釛Ǭ-Fߤb͵&<}R6z푿s -)k3AJ#si=Ydr@#>}~/-U#aE]0v2Er!qPҡ[:jj#Iv+ %=G]Y+p.-SL JqjnWOb+P?;E*YR͑DLW8oȡsC$<ϗ>>u]]9 A ^l48Ck֟Eϼr#~WsI9?AqXs%n_5 me~o,0%ݳhbO^Đ}Bn}2&l%d:Qc#kFZަ]kRw ^r?3NT}LiI*U-ov˃5" `ڌ#U9.1نm@0=xKtWSkcQ8X9yaf`ʃV2:o'A*^8|D޵@ްeCwXnM3bDJZWaXƹ^.qP svjAzm|&%~)3YwQdd(˧<,#(}5 gJ8汄% +~=0k@煏B <bO$B@9|\& ZT/2"j#+c,S2xξb\d%Ulڟ,$ ػsS`;/6ER1mu¾.đNܝ/7pIHE8QAb@Q25JHjbŲyڰ>)Vw1:Mg*Pg+bnk#x3ّޤ͏Xٷfɘ.qa=켪VՁ-qq|F`3Q܋rP6B 57kܚ5f>}103]cmos:Nr\esa,=8^УhU)oV8VOm Mdm=Cll7Je(t@:\yZ]_mV^n_m_j]etUG5r7o>sQ5&;UOv_;T }5LzqЁs{A> =&l}Hf֛xuG)yA&husIP3Dlhj$!|Ğ4).a+SꭃMSjr4cj+ dJ>wNX_kMZj MWTZU`,)sw{CDd}hcԧT98;}z#eAc=:pLh$,uO׷?KL#GZOWVT7mЕqGMł§6wVCqr<^³(_8?ˣ7ք% "y9.F5[XY6hKL;0ŵچ,Ro2"[wC_v ,Ec;.a.?Y?x=}2#!ًaIRfG MD)` RD4bcuv^p;k _XmꑩشXiSC&V?ҩ&\^A׆2+]r,nx|c6=u` 9u I4n`9h #z*vgh_$IцXܢ@3MSzj:(NbmCʳT[9fdf%dl"hkhuxK2ϼeLw'q j)S\֤'w0r1ilЃ'ʟd2b }]~t} I2BCDrvUr7'[Ԉ{<ǜ՜n%2eM|+1^Zv禁`GMGLPaEWqF$ )Q%/sP a;i !Q:B 97`J3b#ث/T""ʹqhL!WooĻb7'@.si-%-@S}L `S5X )С"H{H'US w|=; q^+wWBLJeJ}]']4=^ XK "_/tk,VNUjYg-@4(oAm45 Cm1^䲣PJ+FUe&Лo  Q\ 3~ߵ h}T5/36OIAHxNM?Sk/Y'뢚rb!/= ]5D 6cN~p'< mfk (gGdڋV63]ranQ'M 9 ?+9vp ^y ^ A8%WŧV2ĎEK%'s4a\Ee_6 SUyNԭjrQޯ 8ovѫ簭4@W$Q_$~An0Jhn={"<ک:2}iU[g a*7nƽ|$?BP##F.c34aX;Q> ;gO&5ScwbKS8Zu_h́b3u,Pi!CI+]$Jss '0GD{b?֪Yk678di l*]/ g]60?w +y+my-^B<7~QYp[:s"\Wu0*ݢcv C 1W! M{ǁb瓌SOyJ ' f~Z&V0}h94wF|vzN@C9+NCzt AaS?Fp W|aJŴgƂ8YdT M-G, NϦ,zq; ̻1|O f˃f> 4'z#IP:L|zH09Pvqnُ %&R#8ׄ-?mJwteT!tDV)ݷ4/! HFeY!L-}xi^ut&h*]B٭r+‹H?ޗ؟ E'Ɛh3h)H2iO1<p8WvVO#`,t:YJu"|n[Rn&.Cu5I :>&iRg w]nܖGm3w*^~b Jv>vB{ˋc"U :$`OrI\0\rS4Vbj(lB; mWdLKqb6'7zM&L(vT%&M E6c/~htL67vfuy~_+75&7Ui*'gI62q% *3l9, |G( P\IF EN;$Ubr] UAjH,U^0pLJ+l6_JdJ i.2z=86݁IWglU<;/KZTDxA{~˗G_0 ">g^!.Vx|?>~5t+Y $ZW!)5hYOCp?x ܱucOFoCbO<~EQڝZa"U= :` <9r5Д^}~hP [@JW<1mt I)E57&Z]!zZSc(p;/1 cAԥWb7Gh+u̼sK?i|@#O\t_aPJ9HM'͓5qߠ)4׶\ OHQ| iB_ z2w>٬8x*G=E}27N0}l$\;_ʲL[>b[:' sQG<_M ͭˢX/ `(iq?CFjUM{U8Iۤ50_3tUH3dĿpue#\NU( ĎH~7s|8Óލnƺ$Jؾp[5˷A>udG>Pruý!#,փ~hf59eRRX..7ZC~ Z~D|N]+ͧd^;ې<޲\s5we.8ZKX/pVd${:t7)DԔ>>?(7`KUY˯t9klri)Ȑ$,T݇AR\`vNF_ŷkJɈf? kFMQ-]5`x'e4* addz95m7XS 5FVQؠ &߯{٣!H0+L^4)Yf"/u}*a+F\ܴ b-}3S%*USB{KzPse7K vEdG9#kD`Id' Bf3O+NuC:+Ƒmι(B5нκ- `皘n>DvGEa ='zE.z:E > Ca<ļNRewp]KmiÉz}kP?HΈdap lE;_m!51]&$ދg.} :-f=Ѿq@șKQ,f6}FCŪ$& Zm#)s𳉀?W-Wɓ[sv@˶@zaXp"b2L` M;OG)sS}pRHGEq? 2ܾÊ#6I)*'H$|^#"7p]П )oTO8YA4}I6 {|ПeAp3!6J̃˭A7N 1m* aƜ@/%D.mF~!9r)#fQ T-fsJC1gFfTVp.b'ηS[kڮ /e41S7SŲFVGVmm1FQS~kXTsݥ/XhpywSSaCЇ( E?x ;m֗?k*$ j`q2`eA;+HL4"1f",y)Xl& )#V}~-+ ny~?UZhV5Nm1 ;}WMigʚcLhD@<Y0#OHYW{NWؼ&ʨYpƧ;9$^̈́35ŀ]dj/B|f+ON& ݓYnkƲq/JݫvD vJ½nw+_mTX.ɑUc4Dt7[)׋68` qӽy#/Nhaꗫipve;Rn}.Y!+}lS/n @$bTy&46N;0%F 'b1ljGtQzjB}<(nKrU l=cz9hM[n`iY/>T1!M2,MMPjjMR^d< v⯱FjyvEW^Z-~eu 'ӚP#2Bh鐨B74=_wRP2Eu"%(SIx& cwu=MxQ-u m[<u}ۅu tP|.US6qf6.DY6eR&lS_6BVZ iϡx^ *`O$ku#A'15\wJ[ۡB._t:T! MdȟHuq'{8Q0YѭNMĨAdw:7i!0hVktɘʻSN_R޷DQrfynXp;WwɷVOr,ǖxNfy DzV!DcipSȦ+ٕw@Og,!WR{h@ N^uޏ*s( ͵#fy&Vf\K]RgXxংamxY?Ů dr}0EHYV!Uݥ5y-}> 6g@hJk鉹hrKO%<^SyI\6c +ϑim9`˚ fES=҂Ӽ%E)N~ɾ2fz`$W?*|A;[u`d~[x=;2TlY\=sEpUQox'am0gH_ї/ u8}S&4i<&!Cՠަ}Ƃܾt]!4(ʓ&$\M\*ߤ Jh9>A$JR҉НR]PA ݆㘍Y1(C|X27DI=5zAu> XlhjkڋvceB,N)foWC OM^ƸBlQ`-ALSsn6ah6\iw\AXcW;n-:(6ՍqT<ҎeS* L7tǼ {v88أ忀F]Gan&QX;qތSwUU`mлX3:|- E SmA5Yp=,9SigiRlDC'gPUw*qFOEKi5"y2=OBR52m4%6 "xiв zbdi+E9 ]?D$juL2벹jbڟ[q@Į7AcQoG`[Aodt }]Tf*ä0=@^ ~I탵:I{~Q@{T.!mV"xHB)=ߵ?g"rmK qGޒ mQ9l3Z"ڭϒNSh i~G+P2cn|x ޞg=V`[ඡ(j}T߫KViqU(6ycM ,ݧU ͥN[p6 ᗡƒݸk@WHѶ[XjAGjʧ7 2[a HT +}_nU; v5ƭ!yĽ*(:]]x:Dbl:DqEo+]vz^| kCpZLBj$E@\Ba{49;_7>?@vX,O-3|m mَc49dǦcNZ|jMvtr(Z |GGˆyZB=)۹\ʭǼn czu{76>h07+@)Ϯݖz ׵1;~ 5 !\i7Sw3 ԓQr0Oc4}'hp Ʊ'|ix9ȮԽ]3l;η/Ta8$T8L蹩%Ν1k5{(iax\dSm#ˉ_juvĚniii!ᆵ]=ws6ڸDR٤u;ة'TlM~h7X]Ee2q,qS`D J|7=>, L:JFk=2Q2& n1ۢ)(TDKtV 8ÛVP{)Q ZE@k )%d[(<>_?/_Pvq';}[?~2}uǐ5'tHC:DCuTI+Dz16bT$0-X֬Vj.9W==@h+]̮) dOGNBv"}^j8uj=psZndȯİաNc"RmCMܣ*>.Ik0Nü+Kjڌ.R\gSbK]ORwJ.2ZVvW)w@ދcmf..`g)2UauVʡnhS!S\^z/.5h6_Dy01ITgU-;{ \݀\$12]8u+ a!;g7ꖓ]6Ѵ ,zm^7?$ 4| X]}lFB9T"Itu3si ,zBܿvj_wWȌ4r%Xn;HFpV'l+9LrO+bgPs.ע~k T44/NPOt=&bX&;ٸ|<;͌|@0BW`' 0Rr[ /Qcbb8ɯֈSI.ayQ"si`i}(=wa/ݢv_<8>CTc\]EaUIؑPA:7%AX ry,?/.m/qp]*TĽ\KY>c+-d&lܷ{ 1no9~aZ`TA`JfN,5k Cx9\.z%Phc1(Y8,я r%psohj-tEؤ vs?-'1녇JHz-S;WKcaE?СO8SV$", i-&A+!¨-$BQs3re S˪ь&ѷ.xMLmUY['Ip ICŹ5c1׀ޑ JnrJ1˜􅉏HZoKS;25zGf]#:}y;ܞ!b #0\|8Ɋj\a ax=l~>\Z 1fcmm tMJv;XhRA-"1xv: \Y:9UU3,1AYL&8&~r)_r] %9; DJcG(R?ڧY2Gtk=wTIIC|usSH2#T9cn/%*ai 1̓ӇӼZa.JpEP޼,UiIn*cJIA:  s$ ߯UwMўK5sLRj߶dT?)7gUɰSY-!|I _m+ĵF>fVߘx A{r5ٺ%>XáKևa95 } ^~m#ŝDȔzQfv\q)]-1,J>x!CU~; 5ЈN]Itv5p3u3KI8yFzӁ{|1u؂Qvm=tc%Dž㙐YԌЀEXߣ|6 ]b =R8y5qs=( x0Ѩ{. MQE8SpȷDĖ܎} ۢ5~ks(>PgGyiz&ߐ$MMFax u "w9fM >97BQ~qeG[m}t@ڟ}S-߬GeUwX֍ 0,ͯ,}uaiUrYYfCt1`Dj)|? 'T5iLXrv-דPa'gi_X fi8i57ߣQ1',e fė =E RcUo Vˑ'*9\FKCag?U\zߠߛGȖ؋1V ۜq5MJ8t* jDEAj;8KcQ_J|Q~`G駞3Mlxk1KVĘ4u-?G(XҠ ~:z#7Bo׫٨u]?O7"gjvd(bwNè2iWr22Z@d%qJO_qM*L0En8ҡw%LAnմw>.VK R%!QL8_[o1 /*|\Qcq 5[f!rpNoV+@ 24>(外aPhIt# J JoU(j9%dH42_jJmǐwCOiR8Қ(8QZ4ۧ`I%2sIb AA $ưѫS$A蚁ԴrQ #ugHKapp/"]?zU cdS!phIlBl%:4okGϒ`Ij3 zu6o J]:DTnHYdz@ORJw ’eAHّ¤){B- NCzWP IkH] kVr{1hVX͆>i|o?h cV= v|ȏw[ph+hcoZX}yR[բ*6=nt2 +''Ɩ:+!ZjZ彅N_d!ܣ_㷸wWٛ{B);YOm3"Hdhǽ!}ΫbJV , GWF{:hVnP+ ȉ)>t978V 6ȋPPUW()ʙu3QTb~3B5׬:tuu֥KT:ϥ+l_V!F2B'Zmd9 Yrdi<(b0FRj3(\1=?H{+Bj^(SD&~u< ۤz wS}>l+;Nrwpk1G^v% KF* u: MxE@1Tf$fm6ޡ5S:c/F #ԫF,m9!ܧޱPu¢7A]mQ(?چDZ=vGQj7)xTZ*GtC$%[/!SܪD\ %:hiZ?}Z&#h?y cZ`muK\6.y?wm1NQld"*p~%כل>hS\p[8.W7ܷu$ B1֗3{mkvM֗veW/獛k/E_>Z_=^+B~?/+M{,j B_^هx! Cs !^,?)aDX#<rN"; pP6J*gҌI4`6~\ WVvQ@D  %PloA>IIf7#lkU=%\P>*ϢQ-<./]yIܾ^/;$ڇ *quY7c2hãw@C^f\8iUS9{`:R[H9d톉|㏝s&ZZN RPQ7MO[~RDG|.l\Dnl8nֳ{(4u]RZ 7D)H^ If ԫQrN K/-35K+*STӾt|OQd=BDWBR 㺪ɪk@F/TVY^!QTESڒf,˿2赉z7PRAF3%]i҅>R Vc]ǚ@bb͆%ցnf;nLю?#aKx*;=X2fbl@첹Ir ^ۛ w$#tXU +`Fßc=5C%ޙ$Vgm_=|v v.%5

    F]vCŜ\jhq? 8<ypp5r "׵NX5͹g*NT@?ͩsp^},;Zanj_2 gP:FTq'ζ[z^:p^O J JNzmHҞG #-W'|v1ŭK3" 5s;:}r \+zA=ym; u L}S)E۝%@%(,ebr90o&$0BcA)xgK% Y> t+gQG_\5+{jSO >,CUH5cQm)7R|:胾BHLj 9NNΨ7wy V~(olok'jC=ctci]:= 2K_"5ܼ-zWJ}7`5KC Zor쀾uU XghR>XqF"(kTq^^Z "!ף=n FۣifdÃiWEs(̣$ڨNa qA/P(C&)2B uir6x2 e#5<+ ~ W̶c@#&@LN~F|3njRFr{q1_ lm=_Ř_*1/^|/kLU^QbDk1O?oCb{@)6|_?R$+Sq7ݯ{^hcaF 8"?ګ@+WW1wܠ~%1cU8x*+ΐ\+u'j^0OClgQ+&Y-ۃψ<;K"POruAd] Cw2 Ʈ^.JhGzLR Mrw>K9(h.AV ߭qr@ $aBQe |QHr{CԟET57af-c_1:X+ G%96Pl/]f#X֖G_مl/{0$@]gu7w!Av&pFi7Dra9)xU͸r16d\&:?ߜT,l7KJۥ9FA&)zg5"$7$yJȅI2_ؤ ~N'j-V% ϝ5A ut3 p' -|@x)܋A1.@'}9 R]浄~d!6.VNᎊ 4AZ!ϐ?v H+EX([2=?ȤDEbpL 93PZ}dAfw٩`߯7KRji{!}}8B&+ y%İb! J+R9DGݷ۸#~4l4sHZj^$[ApN8kuۗؖHK)?cAA(X]!ÚnЈPY*M.͓5߽sb5寜Rs#njGA ĒO b- :>扪6&׸g_%ӷ zGhxLj9J_p(C1 XT]*s.W_+G9!?8E 35+:oƢbw8)ׂc*ފ@9~9 3p打i&,'`Pj4Vwmɚ(i1z?s5"Nсs Fڙ(ll):3FX &?^I84PJuII)$)hS^8׸ip@ `bhijlU1#[W$'z|G^{$N})^.Q*Mc#r,\mFCޚ FHM yGҝRpʕ}bM$ ^D<-qfb8 +ߡY"!vjWc_qAGGr!F#ycJ9EYEM i8=F!l,w;7Š4*pKMvt"wQos:J6 cQ]uDQ}~&ύQ FM!~ꁕs Ӷ4@%/iDZ,Ц^+8,R{J_O5Xk#|g'H ΒN!> ߋ!ӇNG9m_֔rf8(}" Vѿo-=D!Hg&ͻ r°X[| ,ek/;dc~n ;:b&N )fRf2Q~(@8–  Q;^gZ)W6rFhp"aO'`m|-7#sXR= 0(8Fz$̷nyz qXp(Kcb Dy`^Hɀf 0CS(8Rd1S -9GBL;<ފC7HzN L }s%7T\5 UG^;ٝ(xh-JdE˦EqcVHB'~&{W3У+$xF3NmX_Qn)A*eX?3JhYR[.~ؑ2:kwqHEUm`Ca=3npt_Z Mb\̌jqGr;1KEy1mO1 [F g3ƛ[tN ~]1ֹI4 LAT-kiPcå%w_㪇(V?$VNsf#+RطaTzh^! x-^;QN}= JvV/u# 44׋3{4iׄˤ/xIғ썣% eŜ]3nhŇyx#rێ̝R`o0_\H'([f; =h!,ac nmjRˣ\mLKkoPtk$~$Yߵn:v`A]!`iE_J߫ou@)-ȮtɧA;RjdW+D@^>#_NMqe8o.vE݈5iƚU M&&"21D xT]p)CUzL}jG$%no<:gkD 戂tYM%5]؋Դ0n&MX7M}cZ+ʻk~E첂 z+Jq>2* G 7%KzbL#S )0:\5HųyV:`>@÷Py0I~ARdf#c0&v1tmѢ&Χ@WT4+" _H(_*Q\h{| ⭿QdU¶xϨ^:l5ZJ],YQ:/ iڴ?2KC,ڍ%{G҈l_쓁_ =ֶ=`&1#㣫<cC:0Â;Ρ׬yܷUguE*ȵ 0O=}J~/5M4N@ |Y(.fh*1qD$] 3ul}޳u1 8Wtߤ^#-??PL_rk֊lv{oD>pWEb inZYf\)St_oJ:Uv 5j[$%O#e7wcjq 'mm~ n}`ʳJJfngZ@[uy,@i>\aJ بi8}*!<:0J Ov~ъ!}2% Ư]+Ku|(Tj䅻r՚?aҝVcu 66mFヲD9;[л3u(Jocd7_􏦳~mMN<[-FnGF.ow#Ku"l= ^#_ۃH&Pۂ{D"%+( . ͇vI}+t$oR"b>/d"q0"IHnq FmVM1x(2pD, G]0 e~յC#a+-Vs%/ޥZ F˥8W6thYfWXoչWȕ>MQY€]H'T(v+X$=ov*0$&.Z˜.:E0i7TL(!kXd2JR/FpH.L^asLn )nXE`] QU_[AɊJ9̒PtnH?_ϛPa@QvЧˍ\,UL96BqEcm<-vĊWU_!>E-'$ZgIKQgs=BN39NFQMZ,E[pe]Ot(i[:h*)@8GTn4YOb#ET%<|juXH8t@q$[9\`8Y[p#/*+ZB:m}8r#1b}m*q v*`Y8-ê@Hx S6%Ja,ϞSʏ =1r'oBb1b>^9`{Vi_ǨhRh/ n0~&:az =yavY9𳲡/ߍ⋞i w8*Eecuʅ/|TwAG Ƣ- =2k{B6^an4KR14cmgp$;L\k9sm/mO=>E0yA$M)ё@# 9 ױ8[V^6W7/4K!QԻ(ݿ.ܣs%kN)LYPzHW`93 T_{qf! 8.;og+ε2௝!!"nRIɬQ(ZJ513 sJxurV&?~g+FE Qtx]I=IxgG3a5@TFbQ0k] NJ_ЩTL\'-&3Rjua߿A$(6K)efTV 3ݳ'?3P]ʃ;!vTŹQ2SڢHh)dOAK;4A3"*UbI׮CdX?2)%Ri%_z,4OFnb#,Jڛ (#Sf }Xd ?=Zxo `<1ϛAӇB,z FmB4 kjևbaxjmhAhǫ)l6 1##ŚRGxJAvg6`8XD:n[c2*BM0lq.S/:ҍ{ xiW3Z*?rvx jg AbAe/;!cW=mJ8OY@7c_@(_X'K߉׀[Ro{)7)m_yU mO(PFMsꚊlav>? BrP^ XndGot\lobHHYZFLD ˚CtEA$gХCBe0H?x>UËFĪ ks 8R¸:Y!ݥ2v#cX7W?/q([mehXKSJ4rB?P2o;ĝOn9&?aM+ T` RR+<ǩ#j2 /Yx|z;ABMTj,}b㩦;l6b}ͱ!dY2?đ6䮾f7/)!M`Ŀ`m!ZQt$Πv .( ۴cסsXPMGWP[=Gm2^p=mbX>\<~v"EgmdY K'UZ US|`Hׇar8c'i DJ{}JXxtihOZ€5ј:+&<[dnuFxTfKaȂmk=6!eDX**.YOeNWa(mhuOxR;S†J>T)djJ)H*bRQPȧ\tOϩg'\^"-]<M10* 3/ s:kq݈;Dd x+&%,NpLy@%?7*eyHW y!\)Ƣ2K ֔-l8 2,/`rf-8YmEьQ'Sf+B1__眗g*5xLO6Q8qzXU\&5D/'C'sPJ3ثhT xegˋyީ0Q駮p9S K$Z1@«8cN5C}1⎲(pd' sHOhs#f zDcj2oG gCFռ*4#h|:Q,gG pư|uk@bVo> O*YwmӅʕ3g$Y`bܞ^s~ f/ib*.KmLGb[]t&mn8j~Liƾ&xai~m" sE!E/*YtX˟d0O"'Km9åjU2ǥ)ˁnu6ױG;6H!j5kղ }mժD?pdrD"VZ{J[&|%9Qc1\׎6 *[]?u{?g޷9UgE7Fw}[iwfw}i0JѱLF;,Ty^8yZA_C9IW^pؿ+ի6rankKXI+ h:W+? SI}/ƣ: 0+9jcؠq'q,v6ЂY9F=|6$M 3ZQK1jX1k8/'(^]'ٽaiNCc5cd5l \)`v[8\y^Gt?& F~&d4qNe/u;O=Q<`}Imsu$Qg"58Ym^h&E`ǫ/%}HGr*(綤QD(p"E4-ػnmx.M|I]!#VC?+0آ*\&55^~|hs?A[{瘾ydzo d XGGD ܱP Q8'xu AKv9uO^I y莼n<ĵ =$?38 ozLѳubH[ Y]=c~p9-"zX'Ƕږlx]pS;"Ri(Xj%tzy2`)j:,ɤ YE]s*[;#.hO)J(ߡ>(Ȳoʖ&h\c!g8G#Ԍ69NB1Rsͫ|72]#Ob Qq{)\F(HT|#{s*v*p\@&(f?LJyE--#2E#`!g]|:C8Gʋ!{j^@ވNߛ<*g@ >z'w1V? ߶iѺ#/6S6o 8ᧇZCN:c5+$߁M*0*b=C- 0-gG *p Tk^ ٍH}cAw1_!B{)or:5E&'A+ỊpV$iE<~,؇;FeObw0]i0-@ה0\t\%M͹6c5 K}D*iVk}*spkS>lV0QmUc征C?zOilP6XPC:!Rx xi0wFgGڴ -yUg[KwQ5cmyWW/7« mfv9bk^l% OR:2nZgd0_!¼?  |jwu*[BW?(ˉtn8%}Q@',^ f5Q**#]zF?~EhxY?]i?39OCrD,T4]1r$zI]{1nj-2.ښ΀5 6(o YZ