sssd-tools-1.13.3-56.el6$>rr?sI(dmM>2h?Xd   A *HNXbb b hb b b b!|b#fb%P%lb&'6'6-6(-8-94:GDbHbITbXLYT\pb]b^bd2e7f:l<TCsssd-tools1.13.356.el6Userspace tools for use with the SSSDProvides userspace tools for manipulating users, groups, and nested groups in SSSD when using id_provider = local in /etc/sssd/sssd.conf. Also provides several other administrative tools: * sss_debuglevel to change the debug level on the fly * sss_seed which pre-creates a user entry for use in kickstarts * sss_obfuscate for generating an obfuscated LDAP passwordXc1bm.rdu2.centos.org fCentOSGPLv3+CentOS BuildSystem Applications/Systemhttp://fedorahosted.org/sssd/linuxx86_640H0KSA }5q"1EQ :bn3] 11m:+}MHOs x?sH cC A큤XXXXXXXXXXXXVpnXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX37400738f8cef2d1783c63c8365dc982441e978114ff575a73f2ec3e1d855268b7d8ed25c10f3f96949c3b06bae485e1a8bd3a9256ffcfd83398fea2d2a4fbf506f7c06b8d4c421d9c8fcd580af633e3aee19682fa86e18f02bafe0010e9370ddd05c09b220c2c09300036dbcd7be67f441693d13442bd8f9cd23abdff722b00d024a636f665f3c205803ab952d6a7d67fc6f9880f2a28fd29366104aadb3b2a074ea22f08e186a8f16066958ff1cb7da80f4a744e9737ad3b619beac9b0a45e31c78f14e9e5e8916dec1155eed908e41983829beb1b4e67230b61da9b84b6217048e1180f9857e4e4cc360177e8a16323b3caff65cfa88c9855e6dc58081793435563d311ebff2595244bb14d38a3f2e835da62f4acf2d5c1be9a9ec1af8ae51fd6440b604ce140da2805f918d80f4273fc16c0c3912cb52b9049a447b55e1662167d9c67bebf0efe19289cb3855d420538049ebcaec5c773f14f7a4d45f5b98ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b90350d84c60491f81ec38582151a779c4e2aee537befbb0bfe275f4af2f4d91a6aca6699600e6c590db54624ae492e7bd5af1db45651ebcb0845e606ee559e903c099c3dd8a113fea8f43eb6155a4354bd4ba2aea406090f3d764f486c3e07556996ab7f4306a908defcace37f1f6c91dc4a2209ba0ef8dd7db7fbce0d4f11aaffa8c15ea2f38ae06aba6778774ec66b34427d8643e9a628e459fca2f53cdd141a70cd03bb230a00adfa378b30947b3c4e4f621421d5598642bf9562af08b264038b2e13af39c3346e820dd25b1cf15cddc65f83e8306b4d14e31d1195d193d3aea0de4f9fadab65b5df315e660634fed1636d3838895735028619c989826cb5cfc92d14b8141c5b61150636295bede5443eef854b35c22858d94d27d2c4cc1809266f7df05620679dee3ef453326967afa37b75389821088071bf478aa26cf13ee8246153513a6490d29df0340aef9b406ecf914d9fd7a8308b0516d609215b4694c32ed1653e72de94bd8799e968a4bbe1b8b2b9b4419c31cc4717c46345219f05981d65f788e6048bc9d1c4c6b217409a3fadc3c5202098a604b69c1049123183ddab8a97d33f0efd00515183d712552a7fb559d420b2382a98bd47a8aeeee7ad17ac5f114eb8c50a94cf87f49ac08f1f6a78c739b1d66a03156b16dacd14df3653c2bd588a3ea18eadb5c1395551ed10740fb86aa2a6e3424550381c92edff47d31c31c18d4e0c2f3420467fa2ff7f54badf57d2e9d03452d0315d4f328bc751516fc4a79bea2e43ff71b134457cfd7ca6f09d9670c757d031ffb545df1350778184cc5c85e2f38cefc1a5fbc5f27546a44f1b906dc11bf7847b6dbfa7347088c3644e8a7bb4fb18fe22400d07409fe8bc6706e9293859f315cc1df71e04a9ef1f4439be013ed636fff2def8917761d7121cb9d135a391457885d341aaf2a349d24a516186ab7287f5a6ab2c03e8afda7442d66c4b6735f7f2b2b644f0901c6555371032147c552448e5bbff22e4dab75d9f0693c61498a6a474cc1da399b24cf6e74b46a9f5b20fbffd2963e906ea123917cfac0a9a145b66952b273068dae0691872ff8b6fc1d5c7eb4a7e96dc9944560779ea8cac92be114f2a615d329b4a010f54b2e1aa82e5fa037daf771988bff39b18e50d73d11e86914487578f0a7d22e14bdde49d0276572df0c93118d7e18851b28e315cd0b690fb3653b48c041c1d18b55521e967929cf5519975d67cc935da4125c3e4031f740ef0691977fa70a7cd8b5fc5c5640e8f39293bf0d0fd2dd002409bb268ee5b7d5c8e9f5a2e4866e6434029b91fbe126e9b533814c2faa0a6eab5b5702367c212a4d67b56ea340dd44345ab427050eac3b66b6369040272b6395539ce39e226e0c922b03d49d6892e97853882c6ba50481d7743d20238c903199c59eadeb3fcefbf87fdedc2ee4ccd8d091076e2949dc5be54449913b808600697856d77d21e8c6b015c713657cce66a0b45917c3984c95ec9dd46b52bbc394c999ee1480a5da334edddaac82b413e6a972b5b871175de92ee547fdf979e6e65996bc3af2f4a47d1389457c87c49d9063684934fa435074f2f345e74b4381acdf58882d46471862ec1f4bb83fbc436f5861d9637216e55a43f3af1f7797aa78e950971e876219bfde4dcdaa55b851b44e3a24f1e6c13aeeb1245750e4a3f529e459b76904c07f2bfe70df8bb00c688dd10766a99d0370dab32750bb1104d0c7ee9490f72aaaa0fd37cafbea446666ab88a65a1350e5bd28bccb7c9652dff2bc19c305118b28ae971fca9a6a1c609bd4ff0118e29c72144475864f3eaf903bbd346374cd618d03aded0b9d85bb22b18ed76d7a520d73a7a98a763f502bc8280d5f025b1ca3d6cd38a1718cc09d1748fc1c2873cefb6307c94a7bdc75d597c98c038251087f2a23619b583a8b546086a0c9f418c4af4c0727e43a693f87c61d7c93860c972436b203a29e6a69f255559306bb17c7f1adafce4335acbd746c86d7eeb69a8f1cd845e74a05226de15ceea5e0bb09516fd684315b32690dcf357948e1648bd97b2a6664bcb857c1e5fc7be27495f3c2e99aa4bdd98a7dc152a75b1135f31dd5ba347cd62cb39bd94bdbcc84c3a6d505dc36e4fc685a81b8b1b79d9807a303bc4a5a9e10c184a1581e77bebc6c6cd32e0a20eae4f4a0e4f4ee90d479a774286ee8dea1851a877114f229cf965f4dd1d49332dc9c066e16edeecbde3014cec0ec6dbc78f271ea0a75012beff5e88701e02fb3e1e4dac8b9420807841bb755e2115c6c6e46b2cdd3c365407be4cfc0d9ba04335d0fd8145b67b045c23d30c8992acd37313ef3a7f7c9b0b703d143f437b5543eba373059805f2e778369398e0af93a55c6c1e962d7a6f476d66d10ff2622f619147e1c39edc58346d17405227e7df1e9f6336c813e618f826ea003f18d714d22e6d3cd717eccc3fc862b25b972d746858157b52105dbf6d37b9b4eb52d2a544e44ce2772184b4746e763ded39ecb4212ae61a05c254b1700fc47890ccaee2d08cb1530610c305cafe9ce2d38267ae622a6b7aa145ef999f128730ee832f3b04f41117e4c0000002c30d2e3b219c4f92c7a3ba309486e1874894b97b9004b2ee16c951aaa1db93c161e54a79d9e5949293b3fb5aca5394007c33971a5ad4b1e0acd537ca6358a3f620ae95b66b058ae3c3ad08e6688a622225d05f16d42013eb4be04c3761a66e93cdf716c743c02f68d39f71441dfdb2686664989e4dc0b629984b2e6aa0cd2008af061a1c3b83a024afe3f6fb073267a63cfec27c8c21fa473980e79371ef2b028e680567692def0429ed9209977bab51786b070bf54f8a69c5ea3aa03efd01f47e44c4d63ebc00dfbde73cb79d56e2d6551404f3f7add230b60c632407d918d3b04644cec57bfcccb0e3b7c5dbb43f8df8167f01ee0e32459dd00c9bad8c021647a6d93c630b21730d9b8d865066d58286fc1ebd25dc5f6119317c9749bb53e25179442acdba94c51e0f07cd3bf74aab44efb6ddb2a9e95cfbd76b4c32854a8c5cbcb7e4b0bac81fd5ff625330e230d3117b78a91c41095fb786fcd6509bad5436f2ea04a06301ceaab2f1490b76e494ab4927e340121a5ac02bbf151ad1fb3ebd42b8f5ec440e2c5a5f00edd5c0efcb19834a87e39d6f3a2a220d64272a18e15d645e576cca2f096d689d03d6898f0afe87ddaca1e905d8c368bb5730f5db2c102b487c47ad0bf8cabba8c91facdd4098f69facf4adf8494ddfb5179a7266accd21f434b602e562d6e11de028ff27abd1bdd4944258d5e246e2c2b056fe6e444ab9e82cfadc4f9b50123f031082ec69b3a844022f9f9b41e8f407d470ab533cd8e2219e5b69d8ecb20c22d514c1e15372e3d1e536a359272218cfa6f9e60ce38eb2539d222c9af9a192a73908ea2cdbf268e9d8fbf457e3eea1a45590ea8f1ad2bee83a70c9ffa0a528bcd61e0eaacb3c85bea64c1c286cdca88c6836a4252c16c48d7a9f2bed2ccdb9d06d4930205b81415331dab055906cae37e1aed485f5673cb60db74eabc239927f99438b7205875343e775d22d65cc198eff590257e709a4921176a33d8c086e1d419acdaa5b60c25afd269427220466f09c759167b9bb3c288d09733d9f372e17df19579ceb4a6852dde577c73c323eab60c92d8a977fdf6e12b1e6e36f9d8cfb1af29b014701d677522bfe6beaaf6739d9f4781c59429b51418e670fd8954e75713bc336838869ce45d31fc9d596cf305654266d0934f3e959c63e179f9ff666b2a79f55a41649897f04fab8e8596269de7f227bada85b84c04bf8214c716b21ed3775ae200rootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-1.13.3-56.el6.src.rpmsssd-toolssssd-tools(x86-64)   @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ sssd-commonpython-ssspython-sssdconfigrpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(CompressedFileNames)libbasicobjects.so.0()(64bit)libcollection.so.4()(64bit)libc.so.6()(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.6)(64bit)libdbus-1.so.3()(64bit)libdhash.so.1()(64bit)libdhash.so.1(DHASH_0.4.3)(64bit)libdl.so.2()(64bit)libglib-2.0.so.0()(64bit)libini_config.so.5()(64bit)liblber-2.4.so.2()(64bit)libldap-2.4.so.2()(64bit)libldb.so.1()(64bit)libldb.so.1(LDB_0.9.10)(64bit)libnspr4.so()(64bit)libnss3.so()(64bit)libnssutil3.so()(64bit)libpcre.so.0()(64bit)libplc4.so()(64bit)libplds4.so()(64bit)libpopt.so.0()(64bit)libpopt.so.0(LIBPOPT_0)(64bit)libpthread.so.0()(64bit)libpthread.so.0(GLIBC_2.12)(64bit)libpthread.so.0(GLIBC_2.2.5)(64bit)libref_array.so.1()(64bit)librt.so.1()(64bit)libselinux.so.1()(64bit)libsemanage.so.1()(64bit)libsmime3.so()(64bit)libssl3.so()(64bit)libsss_cert.so()(64bit)libsss_child.so()(64bit)libsss_crypt.so()(64bit)libsss_debug.so()(64bit)libsss_semanage.so()(64bit)libsss_util.so()(64bit)libtalloc.so.2()(64bit)libtalloc.so.2(TALLOC_2.0.2)(64bit)libtdb.so.1()(64bit)libtevent.so.0()(64bit)rtld(GNU_HASH)/usr/bin/pythonrpmlib(PayloadIsXz)1.13.3-56.el61.13.3-56.el61.13.3-56.el64.6.0-14.0-13.0.4-15.2-14.8.0X6@X6@XS@XOXJXGXF@X@X6@X6@X-X!@X!@X&X X X WWWW@W@W_@W_@WWW@W@W@W@Wi,@WYZ@WPWPV@VJVJVV@VՄ@VՄ@V@V&@V=@V=@V@V@V@VvV%@V%@V%@VVVVVpVii@V\:@VXEVV@VV@VV@VMV2 @Vf@Vf@Vf@UAUUuUn@UmUjUcUcUUUUUJ@UB@UB@U@U?v@U>$U8U.RU.RU-@U-@U-@U-@UF@UF@UUUUUU U U U@U@U@U@T9TTTTTTT@T@T~T~Tk4Tk4T$TTT@SvSvSvS%@S0S<@S<@S<@SSSSSSS/S/S;@SFS@S@S@S@S@S@Si@S@SSS!@SsZSpSNpS 4@S 4@RRRRRRfhRD!R1R%@R @R @RR|R|R|R|R|RRRRRRRRRRRRR@R@R@R@R@R@R@R@R@R@Q@Q@QQ*@Q?@QQvwQkQIQ5@Q0@Q']Q @PPPP@P@P@P-P@P@P@PDPDPDPDP[PPPPP@P@P@P@PPPPPPPP @P @P @P @P @P @Pf@PPPPP @P @P @P @P@P@P@PPPPPPPP@P@P@PpPpPpP@P@P@P@P@P@P@PP@PP@P@P@P@P@PPXPP{P{P{Pz@PqnPl(PaP`K@P#@Oĺ@O"O"OOO@OO~O@OOO@O@Ou@Ou@Oc+@O]@OYOOdON@OLOLOLOLOLO;@O5O1@ObN@NNNN@NNNj@NN$@N$@NN@N@Nx@Nm@Ng\N[@NTN?N:N:N:NNN|@M{@M{@Mߒ@M@M۝M۝M@MM@M@M3@MM>M>M@MM@M@Mx@MM=M=MwkMwkMv@MtMtMc@Mc@MbSM_MQ0@MJMGMA^@MA^@MA^@M.@M9L!L@L@L@L@LNLNL@L@LA@L@Lk@LYV@LRLI@L7@L(L_LLGKj@KK@KK@KK[K@KK~}@K]KY@KO@KKK/c@K+nK"4@KJJ@JJJkJJ@JJp9JlE@J?r@J0J,@IcIcIzI)@I)@I)@IV@IV@I@I@III@Lukas Slebodnik - 1.13.3-56Lukas Slebodnik - 1.13.3-55Jakub Hrozek - 1.13.3-54Jakub Hrozek - 1.13.3-53Jakub Hrozek - 1.13.3-52Jakub Hrozek - 1.13.3-51Jakub Hrozek - 1.13.3-50Jakub Hrozek - 1.13.3-49Jakub Hrozek - 1.13.3-48Jakub Hrozek - 1.13.3-47Jakub Hrozek - 1.13.3-46Jakub Hrozek - 1.13.3-45Jakub Hrozek - 1.13.3-44Jakub Hrozek - 1.13.3-43Jakub Hrozek - 1.13.3-42Jakub Hrozek - 1.13.3-41Jakub Hrozek - 1.13.3-40Jakub Hrozek - 1.13.3-39Jakub Hrozek - 1.13.3-38Jakub Hrozek - 1.13.3-37Jakub Hrozek - 1.13.3-36Jakub Hrozek - 1.13.3-35Jakub Hrozek - 1.13.3-34Jakub Hrozek - 1.13.3-33Jakub Hrozek - 1.13.3-32Jakub Hrozek - 1.13.3-31Jakub Hrozek - 1.13.3-30Jakub Hrozek - 1.13.3-29Jakub Hrozek - 1.13.3-28Jakub Hrozek - 1.13.3-27Jakub Hrozek - 1.13.3-26Jakub Hrozek - 1.13.3-25Jakub Hrozek - 1.13.3-24Jakub Hrozek - 1.13.3-23Jakub Hrozek - 1.13.3-22Jakub Hrozek - 1.13.3-21Jakub Hrozek - 1.13.3-20Jakub Hrozek - 1.13.3-19Jakub Hrozek - 1.13.3-18Jakub Hrozek - 1.13.3-17Jakub Hrozek - 1.13.3-16Jakub Hrozek - 1.13.3-15Jakub Hrozek - 1.13.3-14Jakub Hrozek - 1.13.3-14Jakub Hrozek - 1.13.3-13Jakub Hrozek - 1.13.3-12Jakub Hrozek - 1.13.3-11Jakub Hrozek - 1.13.3-10Jakub Hrozek - 1.13.3-9Jakub Hrozek - 1.13.3-8Jakub Hrozek - 1.13.3-7Jakub Hrozek - 1.13.3-6Jakub Hrozek - 1.13.3-5Jakub Hrozek - 1.13.3-4Jakub Hrozek - 1.13.3-3Jakub Hrozek - 1.13.3-2Jakub Hrozek - 1.13.3-1Jakub Hrozek - 1.13.2-7Jakub Hrozek - 1.13.2-6Jakub Hrozek - 1.13.2-5Jakub Hrozek - 1.13.2-4Jakub Hrozek - 1.13.2-3Jakub Hrozek - 1.13.2-2Jakub Hrozek - 1.13.2-1Jakub Hrozek - 1.13.1-1Jakub Hrozek - 1.12.4-51Jakub Hrozek - 1.12.4-50Jakub Hrozek - 1.12.4-49Jakub Hrozek - 1.12.4-48Jakub Hrozek - 1.12.4-47Jakub Hrozek - 1.12.4-46Jakub Hrozek - 1.12.4-45Jakub Hrozek - 1.12.4-44Jakub Hrozek - 1.12.4-43Jakub Hrozek - 1.12.4-42Jakub Hrozek - 1.12.4-41Jakub Hrozek - 1.12.4-40Jakub Hrozek - 1.12.4-39Jakub Hrozek - 1.12.4-38Jakub Hrozek - 1.12.4-37Jakub Hrozek - 1.12.4-36Jakub Hrozek - 1.12.4-35Jakub Hrozek - 1.12.4-34Jakub Hrozek - 1.12.4-33Jakub Hrozek - 1.12.4-32Jakub Hrozek - 1.12.4-31Jakub Hrozek - 1.12.4-30Jakub Hrozek - 1.12.4-29Jakub Hrozek - 1.12.4-28Jakub Hrozek - 1.12.4-27Jakub Hrozek - 1.12.4-26Jakub Hrozek - 1.12.4-25Jakub Hrozek - 1.12.4-24Jakub Hrozek - 1.12.4-23Jakub Hrozek - 1.12.4-22Jakub Hrozek - 1.12.4-21Jakub Hrozek - 1.12.4-20Jakub Hrozek - 1.12.4-19Jakub Hrozek - 1.12.4-18Jakub Hrozek - 1.12.4-17Jakub Hrozek - 1.12.4-16Jakub Hrozek - 1.12.4-15Jakub Hrozek - 1.12.4-14Jakub Hrozek - 1.12.4-13Jakub Hrozek - 1.12.4-12Jakub Hrozek - 1.12.4-11Jakub Hrozek - 1.12.4-10Jakub Hrozek - 1.12.4-9Jakub Hrozek - 1.12.4-8Jakub Hrozek - 1.12.4-7Jakub Hrozek - 1.12.4-6Jakub Hrozek - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Jakub Hrozek - 1.12.4-2Jakub Hrozek - 1.12.4-1Jakub Hrozek - 1.11.6-33Jakub Hrozek - 1.11.6-32Jakub Hrozek - 1.11.6-31Jakub Hrozek - 1.11.6-30Jakub Hrozek - 1.11.6-29Jakub Hrozek - 1.11.6-28Jakub Hrozek - 1.11.6-27Jakub Hrozek - 1.11.6-26Jakub Hrozek - 1.11.6-25Jakub Hrozek - 1.11.6-24Jakub Hrozek - 1.11.6-23Jakub Hrozek - 1.11.6-22Jakub Hrozek - 1.11.6-21Jakub Hrozek - 1.11.6-20Jakub Hrozek - 1.11.6-19Jakub Hrozek - 1.11.6-18Jakub Hrozek - 1.11.6-17Jakub Hrozek - 1.11.6-16Jakub Hrozek - 1.11.6-15Jakub Hrozek - 1.11.6-14Jakub Hrozek - 1.11.6-13Jakub Hrozek - 1.11.6-12Jakub Hrozek - 1.11.6-11Jakub Hrozek - 1.11.6-10Jakub Hrozek - 1.11.6-9Jakub Hrozek - 1.11.6-8Jakub Hrozek - 1.11.6-7Jakub Hrozek - 1.11.6-6Jakub Hrozek - 1.11.6-5Jakub Hrozek - 1.11.6-4Jakub Hrozek - 1.11.6-3Jakub Hrozek - 1.11.6-2Jakub Hrozek - 1.11.6-1Jakub Hrozek - 1.11.5.1-4Jakub Hrozek - 1.11.5.1-3Jakub Hrozek - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Jakub Hrozek - 1.9.2-134Jakub Hrozek - 1.9.2-133Jakub Hrozek - 1.9.2-132Jakub Hrozek - 1.9.2-131Jakub Hrozek - 1.9.2-130Jakub Hrozek - 1.9.2-129Jakub Hrozek - 1.9.2-128Jakub Hrozek - 1.9.2-127Jakub Hrozek - 1.9.2-126Jakub Hrozek - 1.9.2-125Jakub Hrozek - 1.9.2-124Jakub Hrozek - 1.9.2-123Jakub Hrozek - 1.9.2-122Jakub Hrozek - 1.9.2-121Jakub Hrozek - 1.9.2-120Jakub Hrozek - 1.9.2-119Jakub Hrozek - 1.9.2-118Jakub Hrozek - 1.9.2-117Jakub Hrozek - 1.9.2-116Jakub Hrozek - 1.9.2-115Jakub Hrozek - 1.9.2-114Jakub Hrozek - 1.9.2-113Jakub Hrozek - 1.9.2-112Jakub Hrozek - 1.9.2-111Jakub Hrozek - 1.9.2-110Jakub Hrozek - 1.9.2-109Jakub Hrozek - 1.9.2-108Jakub Hrozek - 1.9.2-107Jakub Hrozek - 1.9.2-106Jakub Hrozek - 1.9.2-105Jakub Hrozek - 1.9.2-104Jakub Hrozek - 1.9.2-103Jakub Hrozek - 1.9.2-102Jakub Hrozek - 1.9.2-101Jakub Hrozek - 1.9.2-100Jakub Hrozek - 1.9.2-99Jakub Hrozek - 1.9.2-98Jakub Hrozek - 1.9.2-97Jakub Hrozek - 1.9.2-96Jakub Hrozek - 1.9.2-95Jakub Hrozek - 1.9.2-94Jakub Hrozek - 1.9.2-93Jakub Hrozek - 1.9.2-92Jakub Hrozek - 1.9.2-91Jakub Hrozek - 1.9.2-90Jakub Hrozek - 1.9.2-89Jakub Hrozek - 1.9.2-88Jakub Hrozek - 1.9.2-87Jakub Hrozek - 1.9.2-86Jakub Hrozek - 1.9.2-85Jakub Hrozek - 1.9.2-84Jakub Hrozek - 1.9.2-83Jakub Hrozek - 1.9.2-82Jakub Hrozek - 1.9.2-81Jakub Hrozek - 1.9.2-80Jakub Hrozek - 1.9.2-79Jakub Hrozek - 1.9.2-78Jakub Hrozek - 1.9.2-77Jakub Hrozek - 1.9.2-76Jakub Hrozek - 1.9.2-75Jakub Hrozek - 1.9.2-74Jakub Hrozek - 1.9.2-73Jakub Hrozek - 1.9.2-72Jakub Hrozek - 1.9.2-71Jakub Hrozek - 1.9.2-70Jakub Hrozek - 1.9.2-69Jakub Hrozek - 1.9.2-68Jakub Hrozek - 1.9.2-67Jakub Hrozek - 1.9.2-66Jakub Hrozek - 1.9.2-65Jakub Hrozek - 1.9.2-64Jakub Hrozek - 1.9.2-63Jakub Hrozek - 1.9.2-62Jakub Hrozek - 1.9.2-61Jakub Hrozek - 1.9.2-60Jakub Hrozek - 1.9.2-59Jakub Hrozek - 1.9.2-58Jakub Hrozek - 1.9.2-57Jakub Hrozek - 1.9.2-56Jakub Hrozek - 1.9.2-55Jakub Hrozek - 1.9.2-54Jakub Hrozek - 1.9.2-53Jakub Hrozek - 1.9.2-52Jakub Hrozek - 1.9.2-51Jakub Hrozek - 1.9.2-50Jakub Hrozek - 1.9.2-49Jakub Hrozek - 1.9.2-48Jakub Hrozek - 1.9.2-47Jakub Hrozek - 1.9.2-46Jakub Hrozek - 1.9.2-45Jakub Hrozek - 1.9.2-44Jakub Hrozek - 1.9.2-43Jakub Hrozek - 1.9.2-42Jakub Hrozek - 1.9.2-41Jakub Hrozek - 1.9.2-40Jakub Hrozek - 1.9.2-39Jakub Hrozek - 1.9.2-38Jakub Hrozek - 1.9.2-37Jakub Hrozek - 1.9.2-36Jakub Hrozek - 1.9.2-35Jakub Hrozek - 1.9.2-34Jakub Hrozek - 1.9.2-33Jakub Hrozek - 1.9.2-32Jakub Hrozek - 1.9.2-31Jakub Hrozek - 1.9.2-30Jakub Hrozek - 1.9.2-29Jakub Hrozek - 1.9.2-28Jakub Hrozek - 1.9.2-27Jakub Hrozek - 1.9.2-26Jakub Hrozek - 1.9.2-25Jakub Hrozek - 1.9.2-24Jakub Hrozek - 1.9.2-23Jakub Hrozek - 1.9.2-22Jakub Hrozek - 1.9.2-21Jakub Hrozek - 1.9.2-20Jakub Hrozek - 1.9.2-20Jakub Hrozek - 1.9.2-19Jakub Hrozek - 1.9.2-18Jakub Hrozek - 1.9.2-17Jakub Hrozek - 1.9.2-16Jakub Hrozek - 1.9.2-15Jakub Hrozek - 1.9.2-14Jakub Hrozek - 1.9.2-13Jakub Hrozek - 1.9.2-12Jakub Hrozek - 1.9.2-11Jakub Hrozek - 1.9.2-10Jakub Hrozek - 1.9.2-9Jakub Hrozek - 1.9.2-8Jakub Hrozek - 1.9.2-7Jakub Hrozek - 1.9.2-6Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-3Jakub Hrozek - 1.9.0-2Jakub Hrozek - 1.9.0-1.rc1Jakub Hrozek - 1.8.0-33Stephen Gallagher - 1.8.0-32Stephen Gallagher - 1.8.0-31Stephen Gallagher - 1.8.0-30Stephen Gallagher - 1.8.0-29Stephen Gallagher - 1.8.0-28Stephen Gallagher - 1.8.0-27Stephen Gallagher - 1.8.0-26Stephen Gallagher - 1.8.0-25Stephen Gallagher - 1.8.0-24Stephen Gallagher - 1.8.0-23Stephen Gallagher - 1.8.0-22Stephen Gallagher - 1.8.0-21Stephen Gallagher - 1.8.0-20Stephen Gallagher - 1.8.0-18Stephen Gallagher - 1.8.0-17Stephen Gallagher - 1.8.0-15Stephen Gallagher - 1.8.0-12Stephen Gallagher - 1.8.0-11Stephen Gallagher - 1.8.0-10Stephen Gallagher - 1.8.0-9Stephen Gallagher - 1.8.0-8Stephen Gallagher - 1.8.0-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5Stephen Gallagher - 1.8.0-4.beta3Stephen Gallagher - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-2.beta2Stephen Gallagher - 1.5.1-68Stephen Gallagher - 1.5.1-67Stephen Gallagher - 1.5.1-66Stephen Gallagher - 1.5.1-65Stephen Gallagher - 1.5.1-64Stephen Gallagher - 1.5.1-63Stephen Gallagher - 1.5.1-62Stephen Gallagher - 1.5.1-61Stephen Gallagher - 1.5.1-60Stephen Gallagher - 1.5.1-59Stephen Gallagher - 1.5.1-58Stephen Gallagher - 1.5.1-57Stephen Gallagher - 1.5.1-56Stephen Gallagher - 1.5.1-55Stephen Gallagher - 1.5.1-53Stephen Gallagher - 1.5.1-52Stephen Gallagher - 1.5.1-51Stephen Gallagher - 1.5.1-50Stephen Gallagher - 1.5.1-49Stephen Gallagher - 1.5.1-48Stephen Gallagher - 1.5.1-47Stephen Gallagher - 1.5.1-46Stephen Gallagher - 1.5.1-45Stephen Gallagher - 1.5.1-44Stephen Gallagher - 1.5.1-43Stephen Gallagher - 1.5.1-42Stephen Gallagher - 1.5.1-41Stephen Gallagher - 1.5.1-40Stephen Gallagher - 1.5.1-39Stephen Gallagher - 1.5.1-38Stephen Gallagher - 1.5.1-37Stephen Gallagher - 1.5.1-36Stephen Gallagher - 1.5.1-35Stephen Gallagher - 1.5.1-34Stephen Gallagher - 1.5.1-33Stephen Gallagher - 1.5.1-32Stephen Gallagher - 1.5.1-31Stephen Gallagher - 1.5.1-30Stephen Gallagher - 1.5.1-29Stephen Gallagher - 1.5.1-28Stephen Gallagher - 1.5.1-27Stephen Gallagher - 1.5.1-26Stephen Gallagher - 1.5.1-25Stephen Gallagher - 1.5.1-24Stephen Gallagher - 1.5.1-23Stephen Gallagher - 1.5.1-21Stephen Gallagher - 1.5.1-20Stephen Gallagher - 1.5.1-17Stephen Gallagher - 1.5.1-16Stephen Gallagher - 1.5.1-15Stephen Gallagher - 1.5.1-14Stephen Gallagher - 1.5.1-13Stephen Gallagher - 1.5.1-12Stephen Gallagher - 1.5.1-11Stephen Gallagher - 1.5.1-10Stephen Gallagher - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Stephen Gallagher - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.2.1-28.4Stephen Gallagher - 1.2.1-36Stephen Gallagher - 1.2.1-35Stephen Gallagher - 1.2.1-28.3Stephen Gallagher - 1.2.1-34Stephen Gallagher - 1.2.1-28.2Stephen Gallagher - 1.2.1-33Stephen Gallagher - 1.2.1-28.1Stephen Gallagher - 1.2.1-32Stephen Gallagher - 1.2.1-29Stephen Gallagher - 1.2.1-28Stephen Gallagher - 1.2.1-27Stephen Gallagher - 1.2.1-26Stephen Gallagher - 1.2.1-23Stephen Gallagher - 1.2.1-21Stephen Gallagher - 1.2.1-20Stephen Gallagher - 1.2.1-19Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-14Stephen Gallagher - 1.2.0-13Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11.1Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Resolves: rhbz#1404697 - SSSD does not skip GPO if no gpcFunctionalityVersion present - Resolves: rhbz#1374813 - SSSD fails to process GPO from Active Directory- Resolves: rhbz#1415785 - ldap_child does not remove temporary files when it's killed with SIGTERM- Apply several more smartcard-related patches. - Related: rhbz#1300421 - Screen locks and smart card is removed - must show a message to insert the correct smartcard- Resolves: rhbz#1400643 - sssd prevents sudo from getting data from LDAP- Resolves: rhbz#1393592 - SSH-CERT: always initialize cert_verify_opts- Revert the ding-libs requirement - Related: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Related: rhbz#1369921 - Members of nested netgroups configured in IdM cannot be seen by getent on clients- Require the matching version of ding-libs - Related: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Fix a coverity warning - Related: rhbz#1382395 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1382395 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1369921 - Members of nested netgroups configured in IdM cannot be seen by getent on clients- Resolves: rhbz#1324428 - [RFE] Discover forest's root SID even if subdomains_provider = none- Resolves: rhbz#1367802 - using overides causes segfault in libldb- Resolves: rhbz#1329378 - pam_sss set KRB5CCNAME with sudo logins- Resolves: rhbz#1382603 - autofs map resolution doesn't work offline- Resolves: rhbz#1339986 - [sssd-ldap] man page needs attention- Resolves: rhbz#1321884 - IPA sudo: support the externalUser attribute- Resolves: rhbz#1299994 - ssh client checks only the first certificate on a smartcard when the card has multiple certs - Resolves: rhbz#1300421 - Screen locks and smart card is removed - must show a message to insert the correct smartcard - Resolves: rhbz#1372681 - ssh with Smartcards - skip invalid certificates- Resolves: rhbz#1329648 - Protocol error with IPA on RHEL-6 - Resolves: rhbz#1329647 - IPA view: view name not stored properly with default FreeIPA installation- Resolves: rhbz#1339986 - [sssd-ldap] man page needs attention- Resolves: rhbz#1327272 - local overrides: issues with sub-domain users and mixed case names- Resolves: rhbz#1293168 - Inconsistent user synching between IPA and AD- Resolves: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Resolves: rhbz#1377782 - sssd is looking at a server in the GC of a subdomain, not the root domain.- Resolves: rhbz#1365218 - SSSD does not fail over to next GC- Resolves: rhbz#1367435 - Intermittent sssd auth failures- Resolves: rhbz#1369079 - sssd runs out of available child slots and starts queuing requests in proxy mode- Resolves: rhbz#1338619 - segmentation fault in sssd after upgrade to sssd-1.13.3-22.el6.x86_64 when upgrading cache- Resolves: rhbz#1324107 - GPO: Access denied after blocking connection to AD.- Resolves: rhbz#1293168 - Inconsistent user synching between IPA and AD- Resolves: rhbz#1340927 - sssd-common requires libnfsidmap- Resolves: rhbz#1340176 - The AD keytab renewal task leaks a file descriptor- Resolves: rhbz#1335400 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1336453 - sssd_be doesn't terminate forked child process if adcli is not installed- Resolves: rhbz#1312062 - sssd does not pass LDAP rules to sudo- Resolves: rhbz#1313940 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo- Actually apply patches from previous build - Resolves: rhbz#1313940 - sudorule not working with ipa sudo_provider- Resolves: rhbz#1313940 - sudorule not working with ipa sudo_provider- Resolves: rhbz#1209600 - Getting ERROR (getpwnam() failed): Broken pipe with 1.11.6- Backport of a more minimal dependency patch to avoid changes to AD provider behaviour - Related: rhbz#1264705 - Allow SSSD to notify user of denial due to AD account lockout- Resolves: rhbz#1308939 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user- Require a newer selinux-policy to avoid issues when prompting for SC PIN - Related: rhbz#1299066 - smartcard login does not prompt for pin when ocsp checking is enabled (default config)- Resolves: rhbz#1264705 - Allow SSSD to notify user of denial due to AD account lockout- Resolves: rhbz#1259687 - sssd_nss memory usage keeps growing on sssd-1.12.4-47.el6.x86_64 (RHEL6.7) when trying to retrieve non-existing netgroups- Update sssd-ldap man page for the recent ID mapping changes - Related: rhbz#1268902 - SSSD doesn't set the ID mapping range automatically- Resolves: rhbz#1295883 - refresh_expired_interval stops sss_cache from working- Resolves: rhbz#1268902 - SSSD doesn't set the ID mapping range automatically- Resolves: rhbz#1298253 - Screen lock prompts for smartcard user password and not smartcard pin when logged in using smartcard pin- Resolves: rhbz#1292458 - sssd_be AD segfaults on missing A record- Resolves: rhbz#1262981 - sssd dereference processing failed : Input/output error- Resolves: rhbz#1290761 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs- Resolves: rhbz#1244957 - [RFE] SUDO: Support the IPA schema- Resolves: rhbz#1298634 - Cannot retrieve users after upgrade from 1.12 to 1.13- Resolves: rhbz#1287807 - SRV lookup for KDC servers doesn't work- Resolves: rhbz#1273802 - ad_site parameter does not work- Fix memory leak in the NFS plugin - Related: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - Resolves: rhbz#1296620 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1283898 - MAN: Clarify that subdomains always use service discovery- Rebase to 1.13.3 - Remove setuid bit from proxy_child, RHEL-6 doesn't support running SSSD as a non-privileged user - Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8- Don't own files as the SSSD user - Resolves: rhbz#1289482 - warning: user sssd does not exist - using root- Resolves: rhbz#1279971 - groups get deleted from the cache- The p11_child doesn't have to run privileged anymore, remove the setuid bit - Related: rhbz#1270027 - [RFE] Support for smart cards- Resolves: rhbz#1266108 - Check next certificate on smart card if first is not valid - Also enable OCSP checks- Resolves: rhbz#1285852 - sssd: [sysdb_add_user] (0x0400): Error: 17 (File exists)- Silence compilation warnings and Coverity issues - Related: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8- Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - Squash in packaging review changes by lslebodn@redhat.com- Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - The rebase also resolves the following bugzillas: - Resolves: rhbz#1270029 - [RFE] Add a way to lookup users based on CAC identity certificates - Resolves: rhbz#1270027 - [RFE] Support for smart cards - Resolves: rhbz#1269422 - [FEAT] UID and GID mapping on individual clients - Resolves: rhbz#1269421 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#1265429 - If the site discovery fails, ad-site option is not taken into account. - Resolves: rhbz#1254193 - Fix for cyclic dependencies between sssd-{krb5,}-common - Resolves: rhbz#1247997 - [IPA/IdM] sudoOrder not honored as expected - Resolves: rhbz#1237142 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1232632 - Kerberos-based providers other than krb5 do not queue requests - Resolves: rhbz#1227804 - Group members are not turned into ghost entries when the user is purged from the SSSD cache - Resolves: rhbz#1227685 - sssd with ldap backend throws error domain log - Resolves: rhbz#1221365 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1215195 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1196204 - sssd cache holding gid values for nss, but not the alpha group name representation - Resolves: rhbz#1194039 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD- Resolves: rhbz#1266404 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1264524 - SSSD POSIX attribute check is too strict- Resolves: rhbz#1255285 - cleanup_groups should sanitize dn of groups- Resolves: rhbz#1251349 - sysdb sudo search doesn't escape special characters- Resolves: rhbz#1232738 - Cache is not updated after user is deleted from ldap server- Resolves: rhbz#1227860 - Provide a way to disable the cleanup task - Resolves: rhbz#1227863 - ignore_group_members doesn't work for subdomains- Resolves: rhbz#1226834 - id lookup for non-root domain users doesn't return all groups on first attempt- Resolves: rhbz#1225614 - IPA enumeration provider crashes- Resolves: rhbz#1212610 - sssd ad groups work intermittently- Resolves: rhbz#1215765 - sssd nss responder gets wrong number of secondary groups- Resolves: rhbz#1221358 - SSSD doesn't work with ID mapping and disabled subdomains- Resolves: rhbz#1219844 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust- Resolves: rhbz#1216094 - /usr/libexec/sssd/selinux_child crashes and gets avc denial when ssh- Include several upstream fixes related to ID views - Resolves: rhbz#1215195 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1213947 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1213822 - Overrides with --login work in second attempt- Resolves: rhbz#1217328 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set- Resolves: rhbz#1212387 - sssd_be segfault id_provider = ad src/providers/ad/ad_gpo.c:843- Resolves: rhbz#1213940 - Overridde with --login fails trusted adusers group membership resolution- Resolves: rhbz#1170910 - SSSD should not fail authentication when only allow rules are used- Resolves: rhbz#1213716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1213822 - Overrides with --login work in second attempt- Resolves: rhbz#1212017 - Sudo responder does not respect filter_users and filter_groups- Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only- Related: rhbz#1211728 - Only set the selinux context if the context differs from the local one- Package the localauth plugin - Related: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Resolves: rhbz#1207720 - id lookup resolves "Domain Local" group and errors appear in domain log- BuildRequire the proper libkrb5 version for correct localauth plugin build - Related: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Resolves: rhbz#1194367 - sssd_be dumping core- Resolves: rhbz#1206121 - ldap_access_order=ppolicy: Explicitly mention in manpage that unsupported time specification will lead to sssd denying access- Resolves: rhbz#1205382 - Properly handle AD's binary objectGUID- Resolves: rhbz#1205716 - Installing sssd-common-1.12.4-18.el6 might install with wrong user account (root)- Fix a typo in DEBUG message - Related: rhbz#1173198 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires- Handle TTL=0 in SRV queries correctly - Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query- Cherry-pick unit test changes from upstream to allow cherry-picking sssd-1-12 patches - Remove unused LDAP provider code to avoid static analyser warnings - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1206092 - sssd crashes intermittently in GPO code- Resolves: rhbz#1202728 - sssd-ad requires samba3, but ipa-server-trust-ad requires samba4- Resolves: rhbz#1203630 - SSSD doesn't own the GPO cache directory- Fix warning in SELinux code - Handle setups with empty default and no SELinux maps - Related: rhbz#1194302 - With empty ipaselinuxusermapdefault security context on client is staff_u - Resolves: rhbz#1202305 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605 - Resolves: rhbz#1201847 - SSSD downloads too much information when fetching information about groups- Fix PAM responder initgroups cache for subdomain users - Log extop failures better - Related: rhbz#1168344 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Fix internal error codes broken when fixing rhbz#1036745 - Related: rhbz#1036745 - [RFE] Allow SSSD to issue shadow expiration warning even if alternate authentication method is used- Resolves: rhbz#1200093 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything- Fix Coverity warning in ldap_child - Add better debugging - Related: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1098147 - [RFE] Implement background refresh for users, groups or other cache objects- Resolves: rhbz#1173198 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires- Initialize a pointer in ldap_child to NULL - Resolves: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Relax the ldb requirement - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1194302 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query- Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query - Rebuild against latest krb5, add a versioned BuildRequires - Resolves: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Related: rhbz#1036745 - [RFE] Allow SSSD to issue shadow expiration warning even if alternate authentication method is used- Do not mark the selinux_child helper as setuid, we don't support rootless SSSD in 6.7 - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1168347 - Rebase sssd to 1.12.x - The rebase resolves the following RHEL bugzillas - Resolves: rhbz#1172865 - sssd.conf(5) man page gives bad advice about domains parameter - Resolves: rhbz#1172494 - PAC: krb5_pac_verify failures should not be fatal (backport fix from upstream) - Resolves: rhbz#1171782 - [RFE]: SSSD should preserve case for user uid field - Resolves: rhbz#1170910 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1168377 - [RFE] User's home directories and shells are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1168363 - [RFE] Add domains= option to pam_sss - Resolves: rhbz#1168344 - [RFE] ID Views: Support migration from the sync solution to the trust solution - Resolves: rhbz#1161564 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1148582 - inconsistent group information when multiple ad domain sections are configured in sssd - Resolves: rhbz#1140909 - sssd.conf man page missing subdomains_provider ad support - Resolves: rhbz#1139878 - SSSD connection terminated after failing anonymous bind to IBM Tivoli Directory Server - Resolves: rhbz#1135838 - Man sssd-ldap shows parameter ldap_purge_cache_timeout with "Default: 10800 (12 hours)" - Resolves: rhbz#1135432 - Dereference code errors out when dereferencing entries protected by ACIs - Resolves: rhbz#1134942 - sssd does not recognize Windows server 2012 R2's LDAP as AD - Resolves: rhbz#1123291 - automount segfaults in sss_nss_check_header - Resolves: rhbz#1088402 - [RFE] Allow login through SSSD using multiple attributes- Resolves: rhbz#1154042 - RHEL6.6 sssd (1.11) doesn't return all group memberships against an IPA server- Resolves: rhbz#1160713 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1141814 - Password expiration policies are not being enforced by SSSD- Resolves: rhbz#1139044 - RHEL6.6 ipa user private group not found- Resolves: rhbz#1103487 - CVE-2014-0249 - sssd: incorrect expansion of group membership when encountering a non-POSIX group- Resolves: rhbz#1125187 - simple_allow_groups does not lookup groups from other AD domains- Resolves: rhbz#1127270 - sssd connect to ipa-server is long- Resolves: rhbz#1130017 - Saving group membership fails if provider is AD, POSIX attributes are used and primary group contains the user as a member- Resolves: rhbz#1111528 - Expired shadow policy user(shadowLastChange=0) is not prompted for password change- Resolves: rhbz#1132361 - use-after-free in dyndns code- Resolves: rhbz#1099290: RFE: Be able to configure sssd to honor openldap account lock to restrict access via ssh key- Use the correct sudo iterator - Related: rhbz#1118336 - sudo: invalid sudoHost filter with asterisk- Add notes about offline mode to sssd.conf - Related: rhbz#1110226 - Requests queued during transition from offline to online mode- Resolves: rhbz#1127278 - Auth fails when space in username is replaced with character set by override_default_whitespace- Resolves: rhbz#1127757 - sssd can't retrieve sudo rules when using the "default_domain_suffix" option- Resolves: rhbz#1127265 - Problems with tokengroups and ldap_group_search_base- Resolves: rhbz#1126636 - RHEL6.6 sssd not running after upgrade- Resolves: rhbz#1128612 - IFP: FQDN lookups are broken- Resolves: rhbz#1118336 - sudo: invalid sudoHost filter with asterisk- Resolves: rhbz#1110226 - Requests queued during transition from offline to online mode- Resolves: rhbz#1122873 - Failover does not always happen from SRV to hostname resolution(via /etc/hosts) - Remove spurious systemctl call on %postun- Resolves: rhbz#1111317 - [RFE] Add option for sssd to replace space with specified character in LDAP group- Resolves: rhbz#1109188 - dereferencing control failure against openldap server- Resolves: rhbz#1084532 - sssd_sudo process segfaults- Resolves: rhbz#1122158 - ad: group membership is empty when id mapping is off and tokengroups are enabled- Resolves: rhbz#1118541 - Floating point exception using ldap- Resolves: rhbz#1042922 - [RFE] Add fallback to sudoRunAs when sudoRunAsUser is not defined and no ldap_sudorule_runasuser mapping has been defined in SSSD- Resolves: rhbz#1120508 - tokengroups do not work with id_provider=ldap- Fix potential NULL dereference in IFP code - Related: rhbz#1110369 - sssd is started before messagebus, making sssd-ifp fail- BuildRequire the latest libini_config - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Resolves: rhbz#1110369 - sssd is started before messagebus, making sssd-ifp fail- Resolves: rhbz#1104145 - public key validator is too strict and does not allow newlines anywhere in the public key string, not even at the end- Rebase to 1.11.6 - Resolves: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Rebuild against new ding-libs - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Backport the InfoPipe patches needed for Sat6 integration - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Resolves: #1085412 - SSSD Crashes when storage experiences high latency- Resolves: #1051164 - Rebase SSSD to 1.11+ in RHEL6Resolves: #1036168 - sssd can't retrieve auto.master when using the "default_domain_suffix"- Resolves: #1065534 - SSSD pam module accepts usernames with leading spaces- Resolves: #1038098 - sssd_nss grows memory footprint when netgroups are requested- Allow combination of proxy id backend and LDAP auth backend - Resolves: #1025813 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Inherit UID limits for subdomains - Resolves: #1020905 - Creating system accounts on a IdM client takes up to 10 minutes when AD trust is configured in the IdM.- Do not crash when LDAP disconnects while a search is still in progress - Resolves: #1019979 - sssd_be segfault when authenticating against active directory- More upstream fixes to prevent memcache crashes - Related: #997406 - sssd_nss core dumps under load- Resolves: #1002929 - sssd_be segfaults if IPA dynamic DNS update times out- Make IPA SELinux provider aware of subdomain users - A better version of already committed patch - Resolves: #954342 - In IPA AD trust setup, the sssd logs throws 'sysdb_search_user_by_name failed' error when AD user tries to login via ipa client.- Resolves: #997406 - sssd_nss core dumps under load - Resolves: #984814 - sssd_nss terminated with segmentation fault- Resolves: #1002161 - large number of sudo rules results in error - Unable to create response: Invalid argument- Silence restorecon on clean install - Resolves: #987456 - RHEL6 sssd upgrade restorecon workaround for /var/lib/sss/mc context- Make IPA SELinux provider aware of subdomain users - Resolves: #954342 - In IPA AD trust setup, the sssd logs throws 'sysdb_search_user_by_name failed' error when AD user tries to login via ipa client.- Print password complexity hint when password change fails with constraint violation - Related: #983028 - passwd returns "Authentication token manipulation error" when entering wrong current password- Resolves: #983028 - passwd returns "Authentication token manipulation error" when entering wrong current password- Resolves: #948830 - sssd do too many disk writes causing delay in "getent netgroup allmachines-netgroup" nested netgroups.- Resolves: #984814 - sssd_nss terminated with segmentation fault- Resolves: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- Resolves: #963235 - sssd_be crashing with nested ldap groups- Apply a forgotten dependency for patch #254 - Related: #916997 - getgrnam / getgrgid for large user groups is too slow due to range retrieval functionality - Add two fixes for better handling of faulty SRV processing - Related: #954275 - sssd fails connect to IPA server during boot when spanning tree is enabled in network router. - Remove enumerate=true from example in man page - Related: #988381 - clarify the disadvantages of enumeration in sssd.conf- Resolves: #914433 - sssd pam write_selinux_login_file creating the temp file for SELinux data failed- Resolves: #916997 - getgrnam / getgrgid for large user groups is too slow due to range retrieval functionality- Resolves: #918394 - sssd etas 99% CPU and runs out of file descriptors when clearing cache- Resolves: #924113 - man sssd-sudo has wrong title- Resolves: #924397 - document what does access_provider=ad do- Use permissive control when adding ghost users - Resolves: #928797 - cyclic group memberships may not work depending on order of operations- Set correct state of SRV servers on resolving error - Resolves: #954275 - sssd fails connect to IPA server during boot when spanning tree is enabled in network router.- Resolves: #954323 - SSSD doesn't display warning for last grace login.- Format patch to configure sysv script differently - RHEL-6 patch(1) apparently doesn't like the output of git format-patch -M -C and doesn't properly copy files on renames - Resolves: #971435 - Enhance sssd init script so that it would source a configuration.- Resolves: #973345 - SSSD service randomly dies- Resolves: #971435 - Enhance sssd init script so that it would source a configuration- Resolves: #961356 - SUDO is not working for users from trusted AD domain- Resolves: #970519 - [RFE] Add support for suppressing group members- Resolves: #976273 - [RFE] Add a new override_homedir expansion for the "original value"- Resolves: #978966 - sudoHost mismatch response is incorrect sometimes- Clarify the min_id/max_id limits further - Resolves: #978994 - SSSD filter out ldap user/group if uid/gid is zero- Resolves: #979046 - sssd_be goes to 99% CPU and causes significant login delays when client is under load- Resolves: #986379 - sss_cache -N/-n should invalidate the hash table in sssd_nss- Resolves: #988525 - sssd fails instead of skipping when a sudo ldap filter returns entries with multiple CNs- Mention that enumeration should be discouraged - Resolves: #988381 - clarify the disadvantages of enumeration in sssd.conf- Call restorecon on memcache files to force the right context on upgrades - Resolves: #987456 - RHEL6 sssd upgrade restorecon workaround for /var/lib/sss/mc context- Resolves: #987479 - libsss_sudo should depend on sudo package with sssd support- Resolves: #951086 - sssd_pam segfaults if sssd_be is stuck- Resolves: #967636 - SSSD frequently fails to return automount maps from LDAP- Resolves: #953165 - Enabling enumeration causes sssd_be process to utilize 100% of the CPU- Resolves: #906398 - sssd_be crashes sometimes- Resolves: #950874: Simple access control always denies uppercased users in case insensitive domain- Resolves: #921454: Resolve local group members in LDAP groups- Resolves: rhbz#911299 - sssd: simple access provider flaw prevents intended ACL use when client to an AD provider- Fix pwd_expiration_warning=0 - Resolves: rhbz#911329 - pwd_expiration_warning has wrong default for Kerberos- Resolves: rhbz#911329 - pwd_expiration_warning has wrong default for Kerberos- Resolves: rhbz#872827 - Serious performance regression in sssd- Resolves: rhbz#888614 - Failure in memberof can lead to failed database update- Resolves: rhbz#903078 - TOCTOU race conditions by copying and removing directory trees- Resolves: rhbz#903078 - Out-of-bounds read flaws in autofs and ssh services responders- Resolves: rhbz#902716 - Rule mismatch isn't noticed before smart refresh on ppc64 and s390x- Resolves: rhbz#896476 - SSSD should warn when pam_pwd_expiration_warning value is higher than passwordWarning LDAP attribute.- Resolves: rhbz#902436 - possible segfault when backend callback is removed- Resolves: rhbz#895132 - Modifications using sss_usermod tool are not reflected in memory cache- Resolves: rhbz#894302 - sssd fails to update to changes on autofs maps- Resolves: rhbz894381 - memory cache is not updated after user is deleted from ldb cache- Resolves: rhbz895615 - ipa-client-automount: autofs failed in s390x and ppc64 platform- Resolves: rhbz#894997 - sssd_be crashes looking up members with groups outside the nesting limit- Resolves: rhbz#895132 - Modifications using sss_usermod tool are not reflected in memory cache- Resolves: rhbz#894428 - wrong filter for autofs maps in sss_cache- Resolves: rhbz#894738 - Failover to ldap_chpass_backup_uri doesn't work- Resolves: rhbz#887961 - AD provider: getgrgid removes nested group memberships- Resolves: rhbz#878583 - IPA Trust does not show secondary groups for AD Users for commands like id and getent- Resolves: rhbz#874579 - sssd caching not working as expected for selinux usermap contexts- Resolves: rhbz#892197 - Incorrect principal searched for in keytab- Resolves: rhbz#891356 - Smart refresh doesn't notice "defaults" addition with OpenLDAP- Resolves: rhbz#878419 - sss_userdel doesn't remove entries from in-memory cache- Resolves: rhbz#886848 - user id lookup fails for case sensitive users using proxy provider- Resolves: rhbz#890520 - Failover to krb5_backup_kpasswd doesn't work- Resolves: rhbz#874618 - sss_cache: fqdn not accepted- Resolves: rhbz#889182 - crash in memory cache- Resolves: rhbz#889168 - krb5 ticket renewal does not read the renewable tickets from cache- Resolves: rhbz#886091 - Disallow root SSH public key authentication - Add default section to switch statement (Related: rhbz#884666)- Resolves: rhbz#886038 - sssd components seem to mishandle sighup- Resolves: rhbz#888800 - Memory leak in new memcache initgr cleanup function- Resolves: rhbz#888614 - Failure in memberof can lead to failed database update- Resolves: rhbz#885078 - sssd_nss crashes during enumeration if the enumeration is taking too long- Related: rhbz#875851 - sysdb upgrade failed converting db to 0.11 - Include more debugging during the sysdb upgrade- Resolves: rhbz#877972 - ldap_sasl_authid no longer accepts full principal- Resolves: rhbz#870045 - always reread the master map from LDAP - Resolves: rhbz#876531 - sss_cache does not work for automount maps- Resolves: rhbz#884666 - sudo: if first full refresh fails, schedule another first full refresh- Resolves: rhbz#880956 - Primary server status is not always reset after failover to backup server happened - Silence a compilation warning in the memberof plugin (Related: rhbz#877974) - Do not steal resolv result on error (Related: rhbz#882076)- Resolves: rhbz#882923 - Negative cache timeout is not working for proxy provider- Resolves: rhbz#884600 - ldap_chpass_uri failover fails on using same hostname- Resolves: rhbz#858345 - pam_sss(crond:account): Request to sssd failed. Timer expired- Resolves: rhbz#878419 - sss_userdel doesn't remove entries from in-memory cache- Resolves: rhbz#880176 - memberUid required for primary groups to match sudo rule- Resolves: rhbz#885105 - sudo denies access with disabled ldap_sudo_use_host_filter- Resolves: rhbz#883408 - Option ldap_sudo_include_regexp named incorrectly- Resolves: rhbz#880546 - krb5_kpasswd failover doesn't work - Fix the error handler in sss_mc_create_file (Related: #789507)- Resolves: rhbz#882221 - Offline sudo denies access with expired entry_cache_timeout - Fix several bugs found by Coverity and clang: - Check the return value of diff_gid_lists (Related: #869071) - Move misplaced sysdb assignment (Related: #827606) - Remove dead assignment (Related: #827606) - Fix copy-n-paste error in the memberof plugin (Related: #877974)- Resolves: rhbz#882923 - Negative cache timeout is not working for proxy provider - Link sss_ssh_authorizedkeys and sss_ssh_knowhostsproxy with the client libraries (Related: #870060) - Move sss_ssh_knownhosts documentation to the correct section (Related: #870060)- Resolves: rhbz#884480 - user is not removed from group membership during initgroups - Fix incorrect synchronization in mmap cache (Related: #789507)- Resolves: rhbz#883336 - sssd crashes during start if id_provider is not mentioned- Resolves: rhbz#882290 - arithmetic bug in the SSSD causes netgroup midpoint refresh to be always set to 10 seconds- Resolves: rhbz#877974 - updating top-level group does not reflect ghost members correctly - Resolves: rhbz#880159 - delete operation is not implemented for ghost users- Resolves: rhbz#881773 - mmap cache needs update after db changes- Resolves: rhbz#875677 - password expiry warning message doesn't appear during auth - Fix potential NULL dereference when skipping built-in AD groups (Related: rhbz#874616) - Add missing parameter to DEBUG message (Related: rhbz#829742)- Resolves: rhbz#882076 - SSSD crashes when c-ares returns success but an empty hostent during the DNS update - Do not version libsss_sudo, it's not supposed to be linked against, but dlopened (Related: rhbz#761573)- Resolves: rhbz#880140 - sssd hangs at startup with broken configurations- Resolves: rhbz#878420 - SIGSEGV in IPA provider when ldap_sasl_authid is not set- Resolves: rhbz#874616 - Silence the DEBUG messages when ID mapping code skips a built-in group- Resolves: rhbz#824244 - sssd does not warn into sssd.log for broken configurations- Resolves: rhbz#874673 - user id lookup fails using proxy provider - Fix a possibly uninitialized variable in the LDAP provider - Related: rhbz#877130- Resolves: rhbz#878262 - ipa password auth failing for user principal name when shorter than IPA Realm name - Resolves: rhbz#871843 - Nested groups are not retrieved appropriately from cache- Resolves: rhbz#870238 - IPA client cannot change AD Trusted User password- Resolves: rhbz#877972 - ldap_sasl_authid no longer accepts full principal- Resolves: rhbz#861075 - SSSD_NSS failure to gracefully restart after sbus failure- Resolves: rhbz#877354 - ldap_connection_expire_timeout doesn't expire ldap connections- Related: rhbz#877126 - Bump the release tag- Resolves: rhbz#877126 - subdomains code does not save the proper user/group name- Resolves: rhbz#877130 - LDAP provider fails to save empty groups - Related: rhbz#869466 - check the return value of waitpid()- Resolves: rhbz#870039 - sss_cache says 'Wrong DB version'- Resolves: rhbz#875740 - "defaults" entry ignored- Resolves: rhbz#875738 - offline authentication failure always returns System Error- Resolves: rhbz#875851 - sysdb upgrade failed converting db to 0.11- Resolves: rhbz#870278 - ipa client setup should configure host properly in a trust is in place- Resolves: rhbz#871160 - sudo failing for ad trusted user in IPA environment- Resolves: rhbz#870278 - ipa client setup should configure host properly in a trust is in place- Resolves: rhbz#869678 - sssd not granting access for AD trusted user in HBAC rule- Resolves: rhbz#872180 - subdomains: Invalid sub-domain request type - Related: rhbz#867933 - invalidating the memcache with sss_cache doesn't work if the sssd is not running- Resolves: rhbz#873988 - Man page issue to list 'force_timeout' as an option for the [sssd] section- Resolves: rhbz#873032 - Move sss_cache to the main subpackage- Resolves: rhbz#873032 - Move sss_cache to the main subpackage - Resolves: rhbz#829740 - Init script reports complete before sssd is actually working - Resolves: rhbz#869466 - SSSD starts multiple processes due to syntax error in ldap_uri - Resolves: rhbz#870505 - sss_cache: Multiple domains not handled properly - Resolves: rhbz#867933 - invalidating the memcache with sss_cache doesn't work if the sssd is not running - Resolves: rhbz#872110 - User appears twice on looking up a nested group- Resolves: rhbz#871576 - sssd does not resolve group names from AD - Resolves: rhbz#872324 - pam: fd leak when writing the selinux login file in the pam responder - Resolves: rhbz#871424 - authconfig chokes on sssd.conf with chpass_provider directive- Do not send SIGKILL to service right after sending SIGTERM - Resolves: #771975 - Fix the initial sudo smart refresh - Resolves: #869013 - Implement password authentication for users from trusted domains - Resolves: #869071 - LDAP child crashed with a wrong keytab - Resolves: #869150 - The sssd_nss process grows the memory consumption over time - Resolves: #869443- BuildRequire selinux-policy so that selinux login support is built in - Resolves: #867932- Do not segfault if namingContexts contain no values or multiple values - Resolves: rhbz#866542- Fix the "ca" translation of the sssd-simple manual page - Related: rhbz#827606 - Rebase SSSD to 1.9 in 6.4- New upstream release 1.9.2- Rebase to 1.9.1- Require the latest libldb- Rebase to 1.9.0 - Resolves: rhbz#827606 - Rebase SSSD to 1.9 in 6.4- Rebase to 1.9.0 RC1 - Resolves: rhbz#827606 - Rebase SSSD to 1.9 in 6.4 - Bump the selinux-policy version number to pull in required fixes- Resolves: rhbz#840089 - Update the shadowLastChange attribute with days since the Epoch, not seconds- Fix protocol break for services map - Related: rhbz#825028 - Service lookups by port number doesn't work on s390x/ppc64 arches- Resolves: rhbz#825028 - Service lookups by port number doesn't work on s390x/ppc64 arches- Resolves: rhbz#824616 - sssd_nss crashes when configured with use_fully_qualified_names = true- Resolves: rhbz#824062 - sssd_be crashed with SIGSEGV in _tevent_schedule_immediate()- Resolves: rhbz#822236 - SSSD netgroups do not honor entry_cache_nowait_percentage- Resolves: rhbz#820759 - AVC denial seen on sssd upgrade during ipa-client upgrade - Resolves: rhbz#821044 - sss_groupadd no longer detects duplicate GID numbers- Resolves: rhbz#818642 - Auth fails for user with non-default attribute names - Resolves: rhbz#819063 - sssd fails to provide partial data till paged search returns "Size Limit Exceeded" - Resolves: rhbz#820585 - Group enumeration fails in proxy provider- Resolves: rhbz#816616 - group members are now lowercased in case insensitive domains- Resolves: rhbz#805431 - NFS files/folders are mapped to nobody user if NFS top level directory is chowned by a SSSD user- Resolves: rhbz#805924 - SSSD should attempt to get the RootDSE after binding - Resolves: rhbz#814237 - sdap_check_aliases must not error when detects the same user - Resolves: rhbz#812281 - autofs client: map name length used as key length - Related: rhbz#784870 - SSSD fails during autodetection of search bases for new LDAP features - Related: rhbz#814269 - sssd-1.5.1-66.el6_2.3.x86_64 freezes- Fix typo in patch for SSH umask - Related: rhbz#808107 - Coverity revealed memory management defects- Resolves: rhbz#808458 - Authconfig crashes when sets krb realm - Resolves: rhbz#808597 - sssd_nss crashes on request when no back end is running - Resolves: rhbz#808107 - Coverity revealed memory management defects- Related: rhbz#805452 - Unable to lookup user, group, netgroup aliases with case_sensitive=false- Resolves: rhbz#804057 - Initial service lookups having name with uppercase alphabets doesn't work - Resolves: rhbz#804065 - Service lookup using case-sensitive protocol names doesn't work when case_sensitive=false - Resolves: rhbz#805281 - sssd: Uses the wrong key when there a multiple realms in a single keytab - Resolves: rhbz#805452 - Unable to lookup user, group, netgroup aliases with case_sensitive=false - Resolves: rhbz#805918 - Wrong resolv_status might cause crash when name resolution times out - Resolves: rhbz#805431 - NFS files/folders are mapped to nobody user if NFS top level directory is chowned by a SSSD user- Related: rhbz#802207 - getent netgroup hangs when "use_fully_qualified_names = TRUE" in sssd - Resolves: rhbz#801719 - "Error looking up public keys" while ssh to replica using IP address - Resolves: rhbz#803659 - Service lookup shows case sensitive names twice with case_sensitive=false - Resolves: rhbz#803842 - Unable to bind to LDAP server when minssf set - Resolves: rhbz#805034 - accessing an undefined variable might cause crash - Resolves: rhbz#805108 - sss_ssh_knownhostproxy infinite loop hangs SSH login- Update translations - Resolves: rhbz#802372 - Pick up latest translation files for SSSD - Resolves: rhbz#802207 - getent netgroup hangs when "use_fully_qualified_names = TRUE" in sssd - Related: rhbz#801451 - Logging in with ssh pub key should consult authentication authority policies- Resolves: rhbz#801407 - sssd_nss gets hung processing identical search requests - Resolves: rhbz#801451 - Logging in with ssh pub key should consult authentication authority policies - Resolves: rhbz#795562 - Infinite loop checking Kerberos credentials - Resolves: rhbz#798317 - sssd crashes when ipa_hbac_support_srchost is set to true - Resolves: rhbz#799039 - --debug option for sss_debuglevel doesn't work - Resolves: rhbz#799915 - Unable to lookup netgroups with case_sensitive=false - Resolves: rhbz#799929 - Raise limits for max num of files sssd_nss/sssd_pam can use - Resolves: rhbz#799971 - sssd_be crashes on shutdown - Resolves: rhbz#801533 - sssd_be crashes when resolving non-trivial nested group structure - Resolves: rhbz#801368 - Group lookups doesn't return members with proxy provider configured - Resolves: rhbz#801377 - getent returns non-existing netgroup name, when sssd is configured as proxy provider- Do not auto-upgrade debug levels - Tool still available for manual use - Reverts: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade - Resolves: rhbz#798881 - Install-time warnings - Resolves: rhbz#798774 - IPA provider should assume that ipa_domain is also the dns_discovery_domain - Resolves: rhbz#798655 - Password logins failing due to a process with high UID- Fix explicit requires to use openldap instead of openldap-libs - Related: rhbz#797282 - sssd-1.5.1-66.el6.x86_64 needs openldap >= openldap-2.4.23-20.el6.x86_64- Fix multilib-clean issue due to upgrade script - Remove old copy from the spec file - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Fix typo in the patch - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Use a patch and install the script to python_sitelib - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Resolves: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade - Resolves: rhbz#785871 - wrong build dependency on nscd - Resolves: rhbz#785873 - IPA host search base cannot be set - Resolves: rhbz#791208 - Entries lacking a POSIX username value break group lookups - Resolves: rhbz#796307 - Simple Paged Search control needs to be used more sparingly - Resolves: rhbz#797282 - sssd-1.5.1-66.el6.x86_64 needs openldap >= openldap-2.4.23-20.el6.x86_64 - Resolves: rhbz#787035 - ipa - sssd slow response with thousands of user entries - Resolves: rhbz#742509 - [RFE] Add SSSD Tool to purge cache - Resolves: rhbz#772297 - Fails to update if all nisNetgroupTriple or memberNisNetgroup entries are deleted from a netgroup - Resolves: rhbz#783138 - Backend occasionally goes offline under heavy load - Resolves: rhbz#797975 - sssd_be: The requested target is not configured is logged at each login - Resolves: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3- Resolves: rhbz#761570 - [RFE] support looking up autofs maps via SSSD - Resolves: rhbz#788979 - sssd crashes during initgroups against a user belonging to nested rfc2307bis group- Handle filtering python Provides in a safer way - Related: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3- Related: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3 - Resolves: rhbz#786553 - sssd on ppc64 doesn't pull cyrus-sasl-gssapi.ppc as a dependancy - Resolves: rhbz#785909 - --debug-timestamps=1 is not passed to providers - Resolves: rhbz#785908 - ldap_*_search_base doesn't fully limit the group and netgroup search base correctly - Resolves: rhbz#785907 - [RFE] Add support to request canonicalization on krb AS requests - Resolves: rhbz#785905 - [RFE] DEBUG timestamps should offer higher precision - Resolves: rhbz#785904 - [RFE] SSSD should have --version option - Resolves: rhbz#785902 - Errors with empty loginShell and proxy provider - Resolves: rhbz#785898 - Enable midway cache refresh by default - Resolves: rhbz#785888 - sssd returns empty netgroup at a second request for a non-existing netgroup - Resolves: rhbz#785884 - Honour TTL when resolving host names - Resolves: rhbz#785883 - check DNS records before updates - Resolves: rhbz#785881 - List the keytab to pick the princiapl to use instead of guessing - Resolves: rhbz#785880 - debug_level in sssd.conf overrides command-line - Resolves: rhbz#785879 - sss_obfuscate/python config parser modifies config file too much - Resolves: rhbz#785877 - on reconnect we need to detect that a ipa/ds server has been reinitialized - Resolves: rhbz#785741 - sssd.api.conf and sssd.api.d should not be in /etc - Resolves: rhbz#773660 - Kerberos errors should go to syslog - Resolves: rhbz#772163 - Iterator loop reuse cases a tight loop in the native IPA netgroups code - Resolves: rhbz#771706 - sssd_be crashes during auth when there exists UTF source host group in an hbacrule - Resolves: rhbz#771702 - sssd_pam crashes during change password operation against a IPA server - Resolves: rhbz#771361 - case_sensitive function not working as intended for ldap - Resolves: rhbz#768935 - Crash when applying settings - Resolves: rhbz#766941 - The full dyndns update message should be logged into debug logs - Resolves: rhbz#766930 - [RFE] Add a new option to override home directory value - Resolves: rhbz#766913 - [RFE] Add option to select validate and FAST keytab principal name - Resolves: rhbz#766907 - Use [...] for IPv6 addresses in kdc info files - Resolves: rhbz#766904 - [RFE] Create a command line tool to change the debug levels on the fly - Resolves: rhbz#766876 - [RFE] Make HBAC srchost processing optional - Resolves: rhbz#766141 - [RFE] SSSD should support FreeIPA's internal netgroup representation - Resolves: rhbz#761582 - [RFE] Add ldap_sasl_minssf option - Resolves: rhbz#759186 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#755506 - [RFE] Add host-based (pam_host_attr) access control - Resolves: rhbz#753876 - [RFE] Add support for the services map - Resolves: rhbz#746181 - "getgrgid call returned more than one result" after group name change in MSAD - Resolves: rhbz#744197 - [RFE] close LDAP connection to the server when idle for some (configurable) time - Resolves: rhbz#742510 - [RFE] Separate Cache Timeouts for SSSD - Related: rhbz#742509 - [RFE] Add SSSD Tool to purge cache - Resolves: rhbz#742052 - id -G group resolution takes extremely long - Resolves: rhbz#739312 - [RFE] sssd does not set shadowLastChange - Resolves: rhbz#736150 - [RFE] SSSD should support multiple search bases - Resolves: rhbz#735827 - [RFE] Ability to set a domain as case sensitive or insensitive - Resolves: rhbz#735405 - [RFE] Option to disable warnings for unknown users - Resolves: rhbz#728212 - [RFE] sssd does not handle when paging control disabled for openldap - Resolves: rhbz#726467 - SSSD takes 30+ seconds to login - Resolves: rhbz#721289 - Process /usr/libexec/sssd/sssd_be was killed by signal 11 during auth when password for the user is not set- Resolves: rhbz#773655 - Race-condition bug in LDAP auth provider- Resolves: rhbz#753842 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758157 - LDAP failover not working if server refuses connections- Related: rhbz#750359 - Major cached entry performance regression- Resolves: rhbz#750359 - Major cached entry performance regression- Resolves: rhbz#749822 - SSSD may go into infinite loop during RFC2307bis initgroups when groups appear in multiple nesting levels- Resolves: rhbz#749256 - SELinux errors with SSSD Downgrade- Resolves: rhbz#748924 - RHEL6.1/sssd_pam segmentation fault- Resolves: rhbz#748412 - Memory leaks during the initgroups() operation- Related: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#742288 - RFC2307bis initgroups calls are slow - Resolves: rhbz#746654 - SSSD backend gets killed on slow systems - Related: rhbz#743925 - HBAC processing is very slow when dealing with FreeIPA deployments with large numbers of hosts Fixes a crash introduced by the earlier patch. - Related: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names Fixes for internationalization- Related: rhbz#742278 - Rework the example config- Resolves: rhbz#743925 - HBAC processing is very slow when dealing with FreeIPA deployments with large numbers of hosts - Resolves: rhbz#745966 - sssd_pam segfaults on sssd restart - Related: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#742278 - Rework the example config - Resolves: rhbz#746037 - Only access sssd_nss internal hash table if it was initialized - Resolves: rhbz#742526 - SSSD's man pages are missing information - Resolves: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#738621 - Lookup fails for non-primary usernames with multi-valued uid - Resolves: rhbz#738629 - Group lookups doesn't return it's member for sometime when the member has multi-valued uid - Resolves: rhbz#742295 - Use an explicit base 10 when converting uidNumber to integer - Resolves: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names- Resolves: rhbz#741751 - HBAC rule evaluation does not properly handle host groups - Resolves: rhbz#740501 - SSSD not functional after "self" reboot - Resolves: rhbz#742539 - HBAC: Hostname comparisons should be case-insensitive- Resolves: rhbz#728343 - SSSD taking 5 minutes to log in - Resolves: rhbz#739850 - Coverity defects newly introduced in rhel 6.2- Resolves: rhbz#737157 - "System error" appears in log during change password operation of a user in openldap server with ppolicy enabled - Resolves: rhbz#737172 - "Unknown (private extension) error(21853), (null)" messages are logged during change password operation of a user in openldap server with ppolicy enabled- Resolves: rhbz#736314 - sssd crashes during auth while there exists multiple external hosts along with managed host - Resolves: rhbz#732974 - [RFE] Have SSSD cache properly with krb5_validate = True and SElinux enabled- Resolves: rhbz#732010 - LDAP+GSSAPI needs explicit Kerberos realm - Resolves: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names - Resolves: rhbz#733409 - Improve password policy error message - Resolves: rhbz#733663 - Authentication fails when there exists an empty hbacsvcgroup - Resolves: rhbz#732935 - Add LDAP provider option to set LDAP_OPT_X_SASL_NOCANON - Resolves: rhbz#734101 - sssd blocks login of ipa-users- Related: rhbz#728353 - Resolve RPMDiff errors in SSSD- Resolves: rhbz#728961 - Provide a mechanism for vetoing the use of certain shells- Related: rhbz#728267 - When non-posix groups are skipped, initgroups returns random GID- Related: rhbz#726466 - HBAC rule evaluation does not support extended UTF-8 languages - Related: rhbz#718250 - Remove DENY rules from the HBAC access provider - Fixes an issue on big endian platforms- Resolves: rhbz#700828 - Process /usr/libexec/sssd/sssd_be was killed by signal 11 (SIGSEGV) when ldap_uri is misconfigured - Resolves: rhbz#726438 - sssd doesn't honor ldap supportedControls - Resolves: rhbz#726466 - HBAC rule evaluation does not support extended UTF-8 languages - Resolves: rhbz#718250 - Remove DENY rules from the HBAC access provider - Resolves: rhbz#728267 - When non-posix groups are skipped, initgroups returns random GID - Resolves: rhbz#726475 - sssd_pam leaks file descriptors - Resolves: rhbz#725868 - Explicitly ignore groups with gidNumber = 0- Related: rhbz#721052 - sssd does not handle kerberos server IP change - Use ares_search instead of ares_query to honor - search entries in /etc/resolv.conf- Resolves: rhbz#711416 - During the change password operation the ccache is - not replaced by a new one if the old one isn't - active anymore - Resolves: rhbz#715609 - Certificate validation fails with message - "Connection error: TLS: hostname does not match CN - in peer certificate" - Resolves: rhbz#719089 - IPA dynamic DNS update mangles AAAA records - Resolves: rhbz#721052 - sssd does not handle kerberos server IP change - Honor TTL values when resolving hostnames- Resolves: rhbz#713961 - libsss_ldap segfault at login against OpenLDAP - Resolves: rhbz#713438 - sssd shuts down if inotify crashes- Resolves: rhbz#709081 - sssd.$arch should require sssd-client.$arch- Resolves: rhbz#709342 - Typo in negative cache notification for initgroups() - Resolves: rhbz#708009 - "renew_all_tgts" and "renew_handlers" messages are - being logged multiple times when the provider comes - back online - Resolves: rhbz#707997 - The IPA provider does not work with IPv6 - Resolves: rhbz#677327 - [RFE] Support overriding attribute value - Resolves: rhbz#692090 - SSSD is not populating nested groups in - Active Directory- Resolves: rhbz#707627 - Include valid "ldap_uri" formats in sssd-ldap man - page- Resolves: rhbz#707513 - Unable to authenticate users when username - contains "\0"- Resolves: rhbz#698723 - kpasswd fails when using sssd and - kadmin server != kdc server- Resolves: rhbz#707282 - latest sssd fails if ldap_default_authtok_type is - not mentioned - Resolves: rhbz#692404 - rfc2307bis groups are being enumerated even when the - gidNumber is out of the range of min_id,max_id. - Resolves: rhbz#699530 - Users with a local group as their primary GID are - denied access by the simple access provider - Resolves: rhbz#700172 - RFE: SSSD should support paged LDAP lookups - Resolves: rhbz#705434 - IPA provider fails initgroups() if user is not a - member of any group - Resolves: rhbz#703624 - SSSD's async resolver only tries the first - nameserver in /etc/resolv.conf- Resolves: rhbz#701700 - sssd client libraries use select() but should use - poll() instead- Related: rhbz#693818 - Automatic TGT renewal overwrites cached password - Fix segfault in TGT renewal- Related: rhbz#693818 - Automatic TGT renewal overwrites cached password - Fix typo causing build breakage- Resolves: rhbz#693818 - Automatic TGT renewal overwrites cached password- Resolves: rhbz#696972 - Filters not honoured against fully-qualified users- Resolves: rhbz#694146 - SSSD consumes GBs of RAM, possible memory leak- Related: rhbz#691678 - SSSD needs to fall back to 'cn' for GECOS - information- Related: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#694444 - Unable to resolve SRV record when called with - _srv_, in ldap_uri - Related: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#692472 - Process /usr/libexec/sssd/sssd_be was killed by - signal 11 (SIGSEGV) - Fix is to not attempt to resolve nameless servers- Resolves: rhbz#691678 - SSSD needs to fall back to 'cn' for GECOS - information- Resolves: rhbz#690866 - Groups with a zero-length memberuid attribute can - cause SSSD to stop caching and responding to - requests- Resolves: rhbz#690131 - Traceback messages seen while interrupting - sss_obfuscate using ctrl+d - Resolves: rhbz#690421 - [abrt] sssd-1.2.1-28.el6_0.4: _talloc_free: Process - /usr/libexec/sssd/sssd_be was killed by signal 11 - (SIGSEGV)- Related: rhbz#683885 - SSSD should skip over groups with multiple names- Resolves: rhbz#683158 - SSSD breaks on RDNs with a comma in them - Resolves: rhbz#689886 - group memberships are not populated correctly during - IPA provider initgroups - Resolves: rhbz#683885 - SSSD should skip over groups with multiple names- Resolves: rhbz#683860 - Skip users and groups that have incomplete contents - Resolves: rhbz#688491 - authconfig fails when access_provider is set as krb5 - in sssd.conf- Resolves: rhbz#683255 - sudo/ldap lookup via sssd gets stuck for 5min - waiting on netgroup - Resolves: rhbz#683431 - sssd consumes 100% CPU - Related: rhbz#680440 - sssd does not handle kerberos server IP change- Related: rhbz#680440 - sssd does not handle kerberos server IP change - SSSD was staying with the old server if it was still online- Resolves: rhbz#682850 - IPA provider should use realm instead of ipa_domain - for base DN- Resolves: rhbz#682340 - sssd-be segmentation fault - ipa-client on - ipa-server - Resolves: rhbz#680440 - sssd does not handle kerberos server IP change - Resolves: rhbz#680442 - Dynamic DNS update fails if multiple servers are - given in ipa_server config option - Resolves: rhbz#680932 - Do not delete sysdb memberOf if there is no memberOf - attribute on the server - Resolves: rhbz#682807 - sssd_nss core dumps with certain lookups- Related: rhbz#678614 - SSSD needs to look at IPA's compat tree for netgroups - Related: rhbz#679082 - SSSD IPA provider should honor the krb5_realm option- Resolves: rhbz#679082 - SSSD IPA provider should honor the krb5_realm option - Resolves: rhbz#677318 - Does not read renewable ccache at startup- Resolves: rhbz#678593 - User information not updated on login for secondary - domains - Resolves: rhbz#678777 - IPA provider does not update removed group - memberships on initgroups- Resolves: rhbz#677588 - sssd crashes at the next tgt renewals it tries - Resolves: rhbz#678410 - name service caches names, so id command shows - recently deleted users - Resolves: rhbz#678614 - SSSD needs to look at IPA's compat tree for - netgroups- Resolves: rhbz#670511 - SSSD and sftp-only jailed users with pubkey login - Resolves: rhbz#675284 - "no matching rule" message logged on all successful - requests - Resolves: rhbz#676911 - SSSD attempts to use START_TLS over LDAPS for - authentication- Resolves: rhbz#674164 - sss_obfuscate fails if there's no domain named - "default" - Resolves: rhbz#674515 - -p option always uses empty string to obfuscate - password - Resolves: rhbz#674141 - Traceback call messages displayed while - "sss_obfuscate" command is executed as a non-root - user- Resolves: rhbz#674172 - Group members are not sanitized in nested group - processing - Put translated tool manpages into the sssd-tools subpackage- Related: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - Also add the updated ding-libs to the BuildRequires- Related: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - Explicitly require updated ding-libs- Resolves: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options - Assorted bugfixes- Add noverify to sssd.conf - Resolves: rhbz#627165 - TPS VerifyTest failure- Related: rhbz#644072 - Rebase SSSD to 1.5 - New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Resolves: rhbz#660592 - SSSD shutdown sometimes hangs - Resolves: rhbz#660585 - getent passwd ' returns nothing if its - uidNumber gt 2147483647- Resolves: rhbz#659401 - SSSD shutdown sometimes hangs- Resolves: rhbz#645449 - 'getent passwd ' returns nothing if its - uidNumber gt 2147483647- Resolves: rhbz#658374 - sssd stops on upgrade- Resolves: rhbz#658158 - sssd stops on upgrade- Resolves: rhbz#649312 - SSSD will sometimes lose groups from the cache- Resolves: rhbz#649286 - SSSD will sometimes lose groups from the cache- Resolves: rhbz#637070 - the krb5 locator plugin isn't packaged for multilib - Resolves: rhbz#642412 - SSSD initgroups does not behave as expected- Resolves: rhbz#633406 - the krb5 locator plugin isn't packaged for multilib - Resolves: rhbz#633487 - SSSD initgroups does not behave as expected- Resolves: rhbz#633406 - the krb5 locator plugin isn't packaged for multilib- Resolves: rhbz#629949 - sssd stops on upgrade- Resolves: rhbz#625122 - GNOME Lock Screen unocks without a password- Resolves: rhbz#621307 - Password changes are broken on LDAP- Resolves: rhbz#617623 - SSSD suffers from serious performance issues on - initgroups calls- Resolves: rhbz#607233 - SSSD users cannot log in through GDM - - Real issue was that long-running services - - do not reconnect if sssd is restarted- Resolves: rhbz#591715 - sssd should emit warnings if there are problems with - /etc/krb5.keytab file- Resolves: rhbz#606836 - libcollection needs an soname bump before RHEL 6 - final - Resolves: rhbz#608661 - SASL with OpenLDAP server fails - Resolves: rhbz#608688 - SSSD doesn't properly request RootDSE attributes- New upstream bugfix release 1.2.1 - Resolves: rhbz#601770 - SSSD in RHEL 6.0 should ship with zero open Coverity - bugs. - Resolves: rhbz#603041 - Remove unnecessary option krb5_changepw_principal - Resolves: rhbz#604704 - authconfig should provide error with no trace back - if disabling sssd when sssd is not enabled - Resolves: rhbz#591873 - Connecting to the network after an offline kerberos - auth logs continuous error messages to sssd_ldap.log - Resolves: rhbz#596295 - Authentication fails for user from the second domain - when the same user name is filtered out from the - first domain - Related: rhbz#598559 - Update translation files for SSSD before RHEL 6 - final- Resolves: rhbz#593696 - Empty list of simple_allow_users causes sssd service - to fail while restart - Resolves: rhbz#600352 - Wrapping the value for "ldap_access_filter" in - parentheses causes ldap_search_ext to fail - Resolves: rhbz#600468 - Segfault in krb5_child - Related: rhbz#601770 - SSSD in RHEL 6.0 should ship with zero open Coverity - bugs.- Resolves: rhbz#598670 - Ccache file of a user is removed too early - Resolves: rhbz#599057 - Incomplete comparison of a service name in - IPA access provider - Resolves: rhbz#598496 - Failure with IPA access provider - Resolves: rhbz#599027 - Makefile typo causes SSSD not to use the - kernel keyring- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP - Resolves: rhbz#584001 - Rebase sssd to 1.2 - Resolves: rhbz#584017 - Unconfiguring sssd leaves KDC locator file - Resolves: rhbz#587384 - authconfig fails if krb5_kpasswd in sssd.conf - Resolves: rhbz#587743 - Need to replicate pam_ldap's pam_filter in sssd.conf - Resolves: rhbz#590134 - sssd: auth_provider = proxy regression - Resolves: rhbz#591131 - Kerberos provider needs to rewrite kdcinfo file when - going online - Resolves: rhbz#591136 - Change SSSD ipa BE to handle new structure of the - HBAC rule- Improve DEBUG logs for STARTTLS failures- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcacacacacacacacacacacacsdedededededededededededeesesesesesesesesesesesfrfrfrfrfrfrfrfrfrfrfrfrjajajajajajajajajajajanlptptukukukukukukukukukukukukuk1.13.3-56.el61.13.3-56.el6 sss_debuglevelsss_groupaddsss_groupdelsss_groupmodsss_groupshowsss_obfuscatesss_overridesss_seedsss_useraddsss_userdelsss_usermodsssd-tools-1.13.3COPYINGsss_rpcidmapd.5.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_groupdel.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_override.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_groupmod.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_rpcidmapd.5.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gz/usr/sbin//usr/share/doc//usr/share/doc/sssd-tools-1.13.3//usr/share/man/ca/man5//usr/share/man/ca/man8//usr/share/man/cs/man8//usr/share/man/de/man1//usr/share/man/de/man8//usr/share/man/es/man1//usr/share/man/es/man8//usr/share/man/fr/man1//usr/share/man/fr/man8//usr/share/man/ja/man1//usr/share/man/ja/man8//usr/share/man/man8//usr/share/man/nl/man8//usr/share/man/pt/man8//usr/share/man/uk/man1//usr/share/man/uk/man5//usr/share/man/uk/man8/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector --param=ssp-buffer-size=4 -m64 -mtune=genericdrpmxz2x86_64-redhat-linux-gnu?7zXZ !PH6]"k%n0}:w{!vQ_JZ0? Mp2%ӽvg6Ђ?;sriH%wD3w&=EOԔ SO2\^wA!V(e sZQ|8t]uc<ܵXNڹ!XjFw#+1hOr~CT'H +.CMP4f Xfie$oG K(le^^-\2!IBoq@.`RP>]\[Z5ݔ+?F"Qغ;fUF3[.H=owm9:[X ̼f0Ԑ j'^z #cnavh)ﯓV/eP3sѷ%6*ê: [W^_T!j4>XWsHOթA gRf%! ;FhV;DozuyXÖG`l\QpDqL>Ѓu5 Gd(#\wD5l/ξ_۽A3p09vœaǩ6w Z7)k.hAiLB#kvI)"@L1AI"[4#{q+׆L=!ym*# ʕdhd\ '2`@}'~#?)se)Qt1E$l^e} 0\>MBhǴF/ċ.RL5WZgL,a,y[c{Y OƋLFs}ʏLKlz;|KFvq3IMMMS'1o&j+b{>VSLp#E$پ x?Tʷ<v} 3eĻ;pJ"͎gN9GUy^s[p\E-::b4-RC1{ ɒET@繂,2Hn4TTn4U"Ӹ;bpҭ8&b)q2n)}j Ur:1aV'BAkxrN6drj wƫW.`n~Nrv=:lDGL*6#Y!|@] WH?N:00 qt%2U]uNT 3!rp=)u6LcD @C`8 j@,tIڪQ@cYjU[?xdQ?$^(' !v(Uq5_#)WK߸$MXH0W:%#~"whLRχ8a a1`_EA?#KN۔OCpT6|^w 즒EP lLq&IR[>p PlVt8Ɛb|G3cf Rt6׆:AyU~ejuAM{YkӏA鳣jSu{Bai |%«'F;%8µbJr>M›/ɦ)r1A!yoa9Jr@/3 !Z-ъkCq[2LnUtmB3sDG+2g%ΨfZlJ%EיH^bJϋV}5ʆT=}LrThC,vR;q-mAW;t:'cI'“2x [Tt40gj@.yv4Dze0ShK(:>rOV.̲k \~8/4/҇A&GZ-V6VV~Z=n>ze@e4#ȣ Y)f !"~-"g)nPCEOt $4lh͌Đu:[vkMk؄ǠeDzpeqy`^]J i ^Ttj׽&/`bJ3Q,W.^KOOD'%>Sh+҈]icm>r6uy_mZֶ CB Xc.T23W %s#oDm-plXeANhA` I!3R1bww svb5.-ŪT^}3cVaçD`6J[x`v07 4ەb1_oW224Z-5{ҿ5gO *^GM 9<Ñ < m)S?s=ACB/9VTU#`P77>؂Ny#L[= ׾){ ˶#A|6#Ň]ׅ8v7Hh ux 5` ,&1>M6d}`E4 և1 0߿gv&C#_q?;r@],;!+D/]۬3"q4yW.ҕ"SE"*a-(2P_- a=l1Z%InъϻȒ2HO'9=̨qZL1VEdtͬp\>V_ϒa/uyC|5ɫ*ً \DE`HF51ј40h蘓X9/(_#g^}4Z0fbYU,י ٧hCSwqVʺjjB/fGW!ɮdGwU%Q]ޗ5"fGdg2]j>LQe~F@Z>V5d_+M2 ޿|͏nmi iݔKx ւ7Ġk&`i^{+,AHKڛHHՉٻ mHџM90(Ֆ[ߏMK D y[DSfMD`jU/|d;e.[~af ڨ;F ( >!3OT Ywз`VJhKVPP舢Ll./6WdckT% ǗwƫM0չq@ov*%BEI0jnP@D r8t«PӟxMCX м UY/a'亰Hs-G S~!*-,^PBh+ZᓒnпP3ƨPz)&kt$]*?X Duj/RdݘpwN;PǂIs@~FV>3.imt(K^rkSӒa7䉢9yWNk6( 缃3z Z Z\ɡ$m lܴVv$Pw^Aro<1;XjǨVE>8^Hފ.xÖ!g j{y TFOBlY9>v3yrh~' 6_$U_ʷ̗V]wy_c7e8{ĴlP[1QZ LM8J w^gZ|@#')H`ޖPt]\7"*2 !{FwOa+$c,J[HhCJ{c0ӖRHƓ!^8JD!ȝ7Nx]ܝ˒4eiYR޾ 8kr1#_3*qNK Ixޒ ѭ1ǖGw@˸\2Fm:U}:RP$BHTyXtQ3MG.}?u ` l:? (pbCw<&I_5=g|YΚ,ޏ0}JCpRvS̀uRo{>O!%,b=4W=[hT8ȗ@sxC5Hq&f@:2SM.Ȯ YƘVק44=F\RyIo : 'ѿҺD,݂*+I@JP.Ou!"fsj # )n p+\Sa-( Vӱ:lwUHG;`C`-80K+j1PsvWD65b\3GɅսLo xmv2ˎ<JJxx kgX<̳o lfꄸJ6lIDGg_!ځHw7&\-^CNI4nʛN3]6e:HRk#36SW VuePj8 f* Nf8p"T027?^Qv$_]S9 pƞ4WC_oWۀs(Z1'`v D!HnqM)x+ߎ2_kTcP~1Gs8hގ.j"T ]ΰ>!KzVZm/$gF$V4խ139|3M6L#m+M=y )ZxkB*Dpwfx{bFz%o}l5t’ ,I%O-K74%Qދqer\BߖǯZ2` pxB~8[L'rShANοpDV{xԷaS:3U% x} P ~v-Ai:OXLߏ"Hj^RL``hMebr>цųql9YHȻjvE#.9?JgTTgX_'7rA+~0[>:}ǰ ]SZEY$z|?Vz)qr];{RpZuLbEbvny W\\2~w|+bj+,Վ*#Рڒ/l6tcAp}Q5qad0SH0XAV}K橑'Sc TX« 錏 mb磻/=,(zjDDTA)6Qۉօ%mN:fArCj=, ULiDEYgwllID۴ W?ńdC _"5[C2~o_rh$ ZbP`ܽ*N=e*h|?#8}V1Ȏ@,]϶qtΞPfXxLdwN֋)iYFe{vM\s7[5P"š-*ݚ>|bQGYmbKmTٳN͊`Ih`6[o'Y,쾬Hs@.X3xuWeݭ lJL G5tΓ %gq[ D15YY$n5cFeDQHJ%8j^йlv> _.pWJ~$5Pqi_ @N!cbm1TmIEm9bz[3c`;ØިlӻJ]lɲkQWt)8w֍s$*'0#p!1h+7EKWj0g@?(|ϱĺ242N17=s+g=@J$Qz둷%5C% Ju/-F>@Y170VFRߥ<.EbH5ѶPy.6;k͘Y}y(gv*DԞ7 [o]"pO&FvtAϓC(8% Ql y(jq˥w y?$6HSuq|j/95vz6ŌҚ Q[`i\<|ЪZ* Wy"x-BHaXhnJ^_ W"PSj`:-d+]S/2]b{<- \&Cq"{[7P  }j2:$lW|8f0s9Ue1ª(FkGUxMCh|&JzӴA|`ݩkggru#*8!6}NL}}S]*|'q8`[3A:gT!6wOʝ/y3a? vbNxl(T[V%Ea}$4e%ulhc_|omq:[/:(v-Y4Gvo} .n{ZԵ#)#bq$sR&9BgL*oMh'8Y#ѐ E r "xp/`t{-pj5 "Wr)PԌG`|jӫyl&{U8tt^";D *h96dR G H>zP5"1UWSI zw gYM5jT:v08G&_Wf!);G6x6,B<YVg;*ǟG~s\ S6P<}ϒ*4zƧ6Qe wLxwTH7h˶"<0.t܄lg-6h^ªr ,v3(yGGс:u!Qr+i4}}cՕA- h=iZD4)X6Q̄Ƒ ܿ_33G"eb/?2Ey]iCP^Q[ >ߐvvFsҳf{,,`DF0:M t xq5W,pjV'zPUo: q~|,1ޣNAU= Tw"} A WbSW8*P%+0 D?h#x&e+2johG\^c>l5z]i"HWXpYGO8|›1O, ~ j8eMP*;>/VPdi&f3 wGp˒;.{QB[!\94Szů[\Q< {G2ѪvVw)ׄ.ۡCOH=}0hPU'$3|2F o:h8׏P?(IAaj|:Fqվ#~$ge,@uGkee9}*RCmϥNhDszZxvHL ʹ )D,OCG>۷[] |AJsulJ$0;B0"ȖÙ<&W&Viȣi*a0LecPơr\^~y5984A@KX@Nd+" ? #("<~/ĨX~N Aу~ 8G(09 xk"B{R5ϔ$%Ɗ2϶,Cob8;8jtCU3apކ1:6*;w ;Nz ,e5Q% t#1W/(1H#ݣY.[:dh0hv4[+Ks:3u6~T)t-QZiM%}35\;jwbIKF Vs] y];'Y[0tpT rtlX;vTF/ma+G̪A6^K !.=;qmAH7ɯiܐ'=`VIoQ[IVNa"KLO~+zJ92pƑSr2[iN^'СRA`a0DəVm|CJOQ0:Eu J/q7<ٹHc[:7$"wWat nk 2ĝfe`Nlf's/OLa9Pi0aV^S,ki/2B$=,T[Zl`,R1%\R-wg#{{@/OYmƇc!۱7L;c\X;ֻZŐ|L؝]{o!a'@4-+@YL'߈u\  hx,5 Pr.8qV*0<>eqpwEYD'ND~XsHQZvJ +퇵A4oٻt :] *aTvT5x+LWI%lHQ1DhmCYw~Oɿ\~ҕΉ$I NhM'wfKJل:a6 J໑âٔSROquwj*St]6вD:t:&3k#cx 93kΜY?H!vr[nOk)(ϥ'kP`8I1Ud^Mfg=5ܟ~~"7g?gow7 ɚ#p*\<$ hX 4?";$kRc5>N:D |p#i"J~jld׉NcNҷwX"#t3VA0!+1?[\ ?nfϑ uv\hsiS&VS+ )0QO'/.NBD”>Xt[uv#O§;8{ު:(g}:XJn- N}$;(q)=Fht.MyU+pՠFͻ{ݔw[xhŤ&4[y8HHXI@N"2mx_ ^ _C9zGBg]g3ٞ6koΑ!n`}=:2 m,HD^\Mo'[GxMԾ-;fqޡ]P20˿@mg\+bs1D4϶|"myP6h@-YǙ!)&55 %\0c٬$0މ@pwb,q'h!Dm%J_n97g[SJua>3@6{&KEXHίˣWAEtپK%pX7:[ȭ&Nm歌ݣ. ȂptAM& u{j")YlX$<ĚOϡNͣ$^' y;$Z m5A+ѱlEOoAuuРvy'q:[5e*3t`:,O(?O-Nm4H -M]D<'܁Shsjxu.n۾TI07 #K 7~e$(D`wZ7uQ$i3g<}C*72zc"[`-:ߺ9"{n:]=,~$@Qu_'1N WkI^cMGn"[9U8wJv{jD)[4r*k{l,9-*Tjʐ?kEfX@l䭾ϝxpHڔi{7w~(ל:.ս7iC$GkVWGleXBP1Hc$Af iDrhwֱ{mMӲ{1&exfP\ ,fȬ_ZzK_0"*~ches.e-mr4Vg4] %%7{Gႛʳs"/cò@25d] 4:8 Q]8yCRrӞz~ow\vd6O'4ӏ0S:!\B^4}4)$ckvi^XM8-D=zyg'GEG(HA{rHsI m>I&6_%ђ3m; בךNBKc9^0Ffg o$[` n <W^Ӯa{S[5v7mӗJ~):r[URpOȊjpjekBVk{AeȵkaЊ[3;@QӮsnp;4lc2?0]pW% (DF;VAS/CGg*SLB'/YeLm6Gz &d@ٚLV8ο㜍t9 @Mz ` |jH XITMg3cy(?'J^@X"At#o]&&Eh.R[xʽ- W~/pbaijWX/2 F=@^P{W 9LSrNMP7.QCE6i6ΐ$셫<鏍DeS/y]m%V0VQ˵YtP=+h鰼,fKul?bav$@;/'6Bك(-YxwI-M)ӽiMA1kG{Jn3*A Xq6_M[_@:)rYD@JhRE?B~zQn(fH?y괥F܃>=ۮtImB)N$X#b:KACΖ Ci`pGM]}.OT_QC k TnuGoVaȢ&?ᇅ=9"v b{oZv([T$2[\j8B|߻GatR=vc:QzD \Yu]"Йô@eMP9za?GǮe@v82ѧ`Ҭ,CUpĶC ;[o}X.lq/n{"|Qd3ȔWTQʒ Ő38\%g`Ģ7N( tHJ<^$ S@~)XLRxYaQzK2Sq߅)}QO#[=OD\*&L9  9mTDXS:Yb p%HF֬r/lmy9(jY 4n5q[ޠjH;#ze1f&&TPEٰ^y@H s{A߷yP`'ct^!D'4mSi1l6nլPpA<6'oa29iTv],Ԇf])'y*K~+}鑃/6z!~j^Kc[GnCڰ~)Q7NB `$ʬ;3WTt\h,NQT~dVG{Q@t\ ȟ;aN>nٴk4s>%mTϭDW/[GD.P,܏F_kEn)?d(Z$ c*D&kjt^1p V^%}PҍL@وQ-3f d+  ޺e{PbY*M0"fRɕ >B8]1N JMu!XLԥ(iJ̧r_gHɋ&'[-KR,MIP/L02+-z.Yܧ$c͔&H69=# P>E^ӘhVA:%߆|ey+9MK%{i`WiuV["Y/($k%O;s}FDy?ҩV諨L5eXoWE(3 B?&iPߠ/D>A ˷ħc)DU~1`g=N*$5ޫ,MT߻Z*V XIb?6qZUmu^Xt.*D':LGQ vuPsމQsaA]Bg0PM " -?~0) .bjjTk`jΜ/Yf+b%mrk$LdUu:y!0C4A`3{u[VS[ps1;=a=P*zncɃj_,HL '(Xv O5DO&PG1LUNˇEB"'}PIq.@Y4.-vѴ;Re[nj ;6j>:+bpe>>տHDsd>f|OtgPDhp(H'XThg4 StN0P1jzSj S3*T xGѽ#ӻX;z:~\^J%U?>q^E"6. Ho J|98&\FɶC3)cSpٱdՕHtbF6.Bv QƏڋQgTh̢Bi:Atz[A꣮@$:@D'D@  DLD[x\oqXLgo_.H?MeM۹a_Q-Lb6${]>–~3A8UC@ "R{F!ImoL2g Z/czi̜EփJBӏJty'aHz{:Z<̇Zd3Y.4; S Fx$[Q+{V7;#*' /X7 0yFd*zɬ槢6/b%NW_fPWB2%e.B. 9`hny!}z9Nb[li6"CxH+<5>)nh"5 |BC 5E;}\ޜMtT7QVnK֞מ2V]~{VNWuu{mOȄ%4NEڄO^zC0 rCܐIp|ȋ'QȠC{l׌E@u~Qy5-fc¾ եHk9١t$:z~%xo#+XMvu;?!L  q-cx*ZakAyy'.-+ltH~s%/Ǯ*':qsjc\dn̄A#r\ckP_"kx G4] 5&I3n~5U6.ŵXtJXwLقƇ(†>;K]v[h/Fy,z=,>O襫6ͳƐE0Ч/ggL6pN(AK 'xDґqgk))9Juܜ<;MXOG4ji3+n̙ZaJ~ʅHpǕk#6yJeά(k,5QA3:E£D{va=Ɋ0KMg'I8\2m`"j3bDҠ_S2+ .]~c~JzUUR)0SÈ>|| _=y8L{&#y277`z%3NbICՒ mщ@|5&h,',;VnL|KUOG8!Ya=O[D\/ՅŪ^M kꑐj Fiɛ[Zz;#Ul/Gnκs't xW e`Ss#;;O.)P|GV"L0\'!z;Þ: ?yUK馉ySZЙ|u#/NQu4!H\A/]h̟aZ:'¢ؔf.# @ #*(!bm:{?y,I*܁:D{#y"HE'@qͷwSڃ&TrVV['񰼖|GKSvSD1PƜY0y-R'30p=@v\l̴D\$4zC}S2f<bliiFk⨛c?nz","@&x *N岞G+ L~[&=dlYtxf&iCoqҶwg8av_qw4n4ݹJE QFT΁ ~ϝpqJW F/{Xy.n"ɜ۾ j@RCiܳF_^%Ny) W= XG6`]2sfXEsF_DIβ>Ƥ}sY">eh46E"~B 1t429x\G67s h柸ANMPkrƳ6:Ѣlyٺ UHX΀u?9;?sј_}U-{` wطx,2{מߔ-ΐ(-HsOS[OO6;v~ӭA&Cj%qo\_gЭj k)9+AR`/F,4Q(MN@97kbmAe>Jŷ*~#Hx뚊&mnQ^O4iKZrelPmM=>+@==6T^3Xuk8O5j~?P7!%ǍOK\g(#Ө ?\̻E*8sb1)#(槇]E턋TUE\Ek/ɁR]ʐ" ' y]x|q"אl¾ID=Ҹ^f.}丵OzKqĉ9ͬṡY BJ-<-P |ݓ \S"=b͎P{Ky0[X!Oۆzʹ[69Iqrk7 0˽ e!)S܂!Uk+d-`Pu$:y=6jbYҁvަ£qqȽer`iIqe+l~Fi)VKA,#ܠXYUQhE%:~ %<@NsO='RmMD O .00nz5 x>[^Z)_~w.땽<+.}̌Ģ@nmc3 Kv˸BHpX(ŭ|(ɼ<1_ '/A(P(1HhwRcDʜ&wE[獄[X).lwN 8BMY b@TڍJ A &ܞ̽'iƩx :zc|0k-k~o-ۿ 나'Mp}(g6MQK }v q*iRl".ᒒ.\GJ^aσ7sU6~B2?+3LW_[S S` ~AƿGj~ nUE@+'*,i<^E3 KQǽI>m߂%?QK27`+zݑ.0v4_zRae5b H˴h0j֎&:dS3RdgLX߇ez1<+;{`629-Tdgp%0[FE.o^Frpd[clJK㖻 $= ,XRMV!ǰ_o%S~jX{3´xsBM|be'fC\ zŒX^'yG9(zp;e,O'3rl&,ܙ O4dPu201`9Tt=nvZjCc+rlB66ɑwb_nbZnSME T5pX}\Hl0H'A̢h-]=';b9m|O hwira8h%EbE]|pY~8O;%PxVh8ڧdH9ݼ|QTP1$vpO. H^N+6n0qsD@;zi` fK65kfPä@z}g?5CI7֐bGij.24, \b>)u/)ȇ O4+26I}`Dxnp""ABeB ,B'";J`t{g5UTw`ۏ/SyAJ++rr)W:K. fQuk,g=E)`,!0p Ŷ7ϣR{l8f?5P4:6]1tY ։]I]:mC>Qqn݋*?-4K(v.uA 1|"i STnH.9$ml$NU'V(F' jv< lNT4`WPL;s^c*rqӪDTL +` .c1t1غcg~ #\4 ?_ӿ%$G%bG Uv۞˰܍hoKLn{woEi}v"ND&PCNLבZ'>>dIdJ]˃sLa"/'H~Y,spf/7K-#0TjL$]BmdCߺKGpHSsϺ<~ғ0̯ yJ5ID>m&j"Ji_,XtX:ŦuW}G^؀SD◟S] :rW/ fc:~6ffNWn9@ekotby7vթsEF{g>tnOxB5F7?]z悸9<̉o۫alT:tq) ssI?ze+u] XQ++}rJ&E+1 gvQ'JJ(5VlI{@/_;gH KbycgGZѰE:iNw#S qWC3槇jVAZklJ,(טKWSrwq52FWT D c^%ͳrwO:Vg;ױJ- 15<ؔU$_&u1{Ľ3as+n $ѯYk?`I_0ă6n^/C5f`3%')EO> cb+O>hwq5XPxq粰GZn==)}!Q(bf1hN}MH"Ge>ZǍ~0u>\C)C"@lHfa Sp)y4cBJ{QfN(pJJPB#:ѯu,iog=# N~\y┋CÄ TW{.;oBV "A9qQw᪋JpWI;ixh8*i  WrUP$E>7},yǞW/܄>w,&n&L(`"O{(&u[C>qαcRî{ȎF%}Vr Xm TUI!s !Sm e8(y U ŝ'LrA6d 5,@ҁ~t23sr:@Զ[t!ƵBi# 3*Zo5 AW]e R~m]FN{yjfYR\&Hܝ=.!䐸:_gp GzL~2[F6 QqpvxvvMI@=`$')?6eFY $N&Gh}7}.=TUkЭg;$4CV=n$*eϡyqc'X"Mkየ}zqq%64UEP[,(ӻIuq,xFX4] 3š`]$dlTbhe}.0brwŌP0&L}{ǾkqUWYcRlU*ө2L v&ܤ_|8R`C)"ћޓ޷Vbw{FqN YZ1+U7h< GxX٭źniqf|B MYy9B_KzPbVk5l`lUyCa.FvYzz%0,,`_AJzFl ҼkXRliH햇 Mk_ s(Qnys5jV+J yde3Bx6ChkĽѹ篙F^.Lw,[VLM,ݤjmɔvXhՑǖ !qbE?U"޲\/.S@3WK_o镧v#D}Q)R;llZn _gID?NEb+#EUm^)BwyF=-[-hl.BdzaRv_O̷f1ۧeXOzmXTQig&2>2Ccx{ M3_۹`q i# l @Ɏ!zs}`TaK>Ѻ+ve,&yP bؗ7w5.bZ'mL o?5wFaQm{&[^a\B_%b촵Nظ$w'?j!B)`e\aQZvg#:i#2ixC^r^=V$5W8|zqtU+)4WT,0]i IqR+*WJ0Ł~vS74\Ѓ5B ~= DAq$wV74B M`pR9cįޫw&Ur@iirn($4E8y3&1AJ"ޟ (86pVUg -$UbIC,OD8lS)'a(=$Jm]Qt¯oJqe-+pQmi`@of7eݎ,dڰ%WYUz [}g.=tmX ޵, =+wqp*S=2~nlsZa.. p%]w~i %γuRM1BPorn׸㩴ĝN:tבUvq,DqT臘ct4z'{dȖ+gʎ)kSԡ [DN/A_}m}_{bg0:av~fR|ƷTmWլD[f9,!шdb[\RnO7J+, IK:j7wVdR0kD]KK!Uo (n,2 "@5cU6Τ}]VjqrVݟ=dD*7Y&7e3Kg#zzY磡iW=._g#)Tpa$+l/.Km uD, shQ^/b4rtM&nTmMUEzi&ƬDkzn`9X}8LNAU?͘$恞R3rU,klvB9ȑodIYhL`Ӥd]z3d/L5$dv,J2}~^œ[ 85@x\s[Oe!~K+fb ,66f6[#A} ŧjCA75Mpc +3oy*wGv_nd3)l )JQ:cXnuTPegG$<Ԃ^JjMSѢ;NTƯiD [tZy45`>jӃ̮QQ"V!2Gro3ǀsf,Ng('fOį\A[WZљŏC!0!H<CMwJ*}-oo}LTL"Tqڸuk Ef9*u^hHB*:X_ DÒhAhO{B%] ӕDCx)ġ  r% 94+z36gEtz+/[ Q&zrSßN VدP Zln3gogĉfuPD4}w!iqz? 1°0)NW*Af nL/z~ <' Ω(-ZNsW&_Ie)~Saoz?;H{ zQANz#`5͞(!+.YW}YUujB\]Mhl.T[l#7 *;"DSioeg~FDۆQ1rrp) L޷I>E>!j6},"f-~srK,W3V7*n _-&^Fk|c-PPyr\cW}EGŻMTBD*`'ڤC^Oa"k)ʇI;zHmWS~1 #,N=s/s[6}`&6OL0Xx)dU+ ^Na(*'VΛYMq;^gm|U"(r~3%yW4jO1փFfVeda|mQrDnͣp:%3~٫_ư?8Z挣N|^oSeCg(i; D5 gK舁_$w!O3IB'“F7&q݇1G!лb8/S0t.g*(Urw5 *as'Q61}hS3}'5Nȉ.@ 5}ԟoм/B7gjK? zwXHwXNFJvc*r\3(ȯg?~ZMNb6&)')^+m[6C8fyuE-}F{N6+2,tHTa?Jڏͽ7mLf:6acJьD֛e^dPc1K Y>M/Q2{3 ͌$p\\S2*5-dT5<IIICN5as W)qU7SY~M_˂mtyC Lh]hDFD|[1wܧޏ!DjAN Ĺ`@Wzyl}1}7{5ï/IG4yrdDb Ы4͎43iV6*r"allp`%e[*޼rJ,ڳk !lj8z>,W<%<`V U7c/ŠqPAK;"@Zu͐0*Dd{ wΡ9u{q)޺9 Z#9V?3NJ,cq:ro!F8x3a[~}Ԭg<ΕX.{ˌODdŁ}±;Nm>2yrt; U$ǣ2❛CvR0}:bY0̓)|:O'D]x-:rO%m-X`? (G^#xGJNCz3)y5]P56qZWݱĺ6+и%}[2k&x$?4kt]s~wzWh-?z!bIULdb@Xپj̋fD>rޭБ'_~ĿtL qZO(SL>;fOJPl]{lLZe~.8!P5`(jF+#|$!@Höy7Ʀ Hi6[`7 ǀrJR5;zm`BZE JJUH׺Li|`vhE']@cNơJ9!6o!%L1xlܯ{C"yx(] N NMbof4m01'п7_XȺۭ֗$oMס+ 9wn0z )AeYVGNLU@멌*q}@US(QQrHz}])78{/abQue2}]#Da4xu7ľNO/.ԧA-zHǺ+b.a e*sZ-9Xz[2/ezd6 ^"C6@8s% B҂hKc%@FKԋd늨6c " qs0&jpM2 ys{^|wX4s~MaӡH\Y@XYM9 yz,>n45C،5(zx[\]*G؞;Ϋ͛Hկ 5#TGGu/^U;|3ʦ@s@'r_A}D? \iѴ G"52ř-Xzhfx:NUT,@pGd"xx?!O˹eؔot-r  \XApo$ \ 0Q)Z*9m&3!fc?-w ?ldO4F54r)QT>ѼGT7S,%\D`"BFKP:>+'o`ܷʓSw x'?n6 v.G49!-u4\t( n4_Kh:gL`VcF%n/\uJUv [Ԧ'3v2PpjaHt F$Mg&yo^u$3GfﯱtR﵁?⍋] nZA'VQgz@( z2Z &j&|} ƴFP}[g?FgƝT Uv&r?S)>z"N\VrU)l7w2kr]U7YP63-ˮ9).0?*-Ql4uxe1dh& ^e5{y7W@җ:OJΕCi4nQ9Qi$)Ӓ&kB0ˎrqNc/DDomlf֭ڊdJQ QDW]®󪧧,ƞ5p NzG3XO1.&367 #bI9$f[;+F3VSnQwA4 5'@aV׉ IkY=8,dE*ٙа4RT=KZ5|Q%!u|WiZ1h" ήv[3Ӳ*jOŽsW=[?p>kr X=bNF6=Cq:7av$ޯCn+(ORu=2z`;y::FW*@Rd Qnf VKsfR\ce7kB._SA^ ӔZ,,eם5{;:eoӟU=挜f_d u* ]k폈-1nWI\8;Eo . >M >K u@Ru>ƹMBa@VWkx 5[6qY1 #8g8 _8veMKBHk<m.3omNdi@%)wÝЛm*i0:DUj5c@+LB8.>֘ mL]ӲLi +9T®N\yy/v8&WItGgQ/#KSbU3.5$L-|`Qߨ 7j6hWP ?YT;.- 2e_>3H=iTAXka9]o:[!xo]j _@Tւ<orXU+kp]Qytn")$`dI%1C ajL P$@98VmB$7T|l$A{E5Db3bS;V?0̤%ڨ~$<:Jx[ #T|[_MLBt.Κn-S&i. !3b>AA'zL (uOSnHYoÁSF Hن[=вywT'|,aSA7k ]7°;Fb^VSj7C6ڗq e;I!u9_ٿxgxUtM6*Թ3>jZ$@W_J&;M?٭5p?OPiaE|rD}x֢Fָ&{TۗH+Grp):RsCsT:_d#6x]\/zT-XBj3oeGjrVi]x_HhrT!.^wBxX'#T['rWIaP }l?J *HQ$?[e"<eq#$0hhSλ=5o|M/vE! S1}0D)Sp~ m3ϝ Et_tVV]U71ݡ9OO Wz> FiFZf5Btq378!FA-}MEXō@Е8*Nݥ@LW RlEnKBiX_/6V6ksNTE)"-'Po=f`odC}PC~xY%wh!VZ6ۘkFǣXC8Hee~IHr jNDC-u}rײuҚC 13~8>-+Fa$H_ >] [mS5FTJuO@)>^&4_Md5"R8eT9I0 R"FUvGHـ6=`x@I}Iap5mt2fY)?F7޳}Dl+Cf7\/sTBއRYNkiov{A鋸b:Vu#^BWY}akƽVw.߭N6A־3 w ֊e8hh>*]9k Png@ߤFi%rp6=9?bKbGwbNjD :Law60~0d#zs[Bά-14 /5}})f#w#Dl'!ľ-La6ϻM̑I ЮK nL=\iu5xTn<'C0B7}0{HK.Gg\q8s0 "lE'c2ğ;0ˣIǩh˗LZ6/ ѭ8!UFڰ4jpz6sJu ~F Ou|LLv\YkY)%Op:.1SP&8hۗX^s"STGk1n3DOՅ?H/R8 ٽmcw\ >F-IKR ڨ4-XdYFTyk m'_ Q- uQa2r~c<3ԤrA _Kaq~ LotpA4m~>kBa8NmTʽ Y76EGfX.?~ϻ?ơ^9Cwme( ( Fbcϧ6fJ"3k vSԁMRZ)VI.'D ؤ ?~*֤_S2U\ߦ,T~:"4ػSL n82u,VAH !*TWDiZNˢKcghrM2OCzT#."oUmW?rfvxQ?0 95u񉹬%@?*av +TEdޣP]lE  ?QcAlR{N5.tkѮUDrCw椥Ack%Yĭ1M=2:?15^r8J{-_{5Y*Ȃpuk!"Y > MI_L˸H[N(P?h2Oh#L KoNum(`@4ѲUVg0$qVՀ).HkZzBXgPdª I3{0C@քϫBaPH*h΄kN#|Rz@~tr:EKNn+>W~P#`>QxeQ$$Q e+ty[A F˒#s8q̈ E|0 iq^1z;&# $SN"Zp~l&Ŕ(kNFQ7Nj!ųu~(ޠ:W=\6dZ?߀^e,1Kc`B[bפUWH))zLx&**tNF^Om֙9o.9%;l]ljtxNUg3˱-g_\jγ02|B5*>Ÿ>t0noӇg?@t”C h4w< vWMi̬@=[zᆡg]6HSؾZ K&$ٍWم8dXT)k_v X`n9#tk|I?N)۠GfSeԦv1{=yk)ך[Bery2/wTPKH܌Pb~%u iˏ6\qd r=!1K:7{zVʩ_hoX{?2X)Ni)EcPfqXQQӡVڧ}uC&mOs/)*VpJUZY:YؒDQL1ebV4fK Ur]=IKɐ4PjI #\nUWz4X'8qj¸eUԣQƾ9d0 ? mtSY`EV@k#BM Q{:Ds%pE"%p3dmR,q(S*Zx?l PsH>*K?MU20Һztx}UjG\~ 6j| kωkq 0a>=eC$ '!׊Щ4tŊ+RdLB}nÐh#F)x^` ASܵGMb۴]hY1׉;eo~@o> iVe[/B+3>g{lqFG[$jtJ<`6>?q=&xăfWYyQ&Pۧ! `OKI6#ApgdR8 ]nA$ATaQnj̭w?w@\'7'Ybw t{Bl^BHЋ$<j&xxWM}vT(E.;50lzksè Icf _{H1tԏ#hY~켧X>ifk% W{ǎx|;i2FwA4{fKWD(-[HM+=g%cn_.TǛjth>[&8 -FκwBs!gJe/ Ard3PPS_ u  AU^o6bܫG,!xJu1v]NJB#jґ pr.);%+Qt=BZクTPV!5X8z2-85"~Kdk%uJY/$X{V)J~HJQXKɯ1CXgBAj#. i@6>߻sG|JA+NSuDD/ 8.&VI`thP>n ( ry`_aאYɃVqf$^7R 1DM&Ǹדpc܅͋Y?(/)@7Q]űhÊK$M+t띊\@5mnilI[mĭ!IQA48•Ԥe72 /"߳)3Bxl3p%}uv4'(c=f4Umߍ)f blLֆ)ctq LJ }Uր|[]D\_KU ":eԟݹVhM5AQעS5*<; T0>l?ыVB;j6E}|PC-kep'PD?3f"S1 +H5 =$1dOJXPI5WJtM"D=h63=&*D[:, 'dHѺV(Mp`1<mHL|7}@1j%>84aPI%L&Z!8Ej"]aGj:{H󈨋FIhwP:6ƕ%H&601+sP-t|29 5Xia[NҗC[kWBؼ?1^hUn&&Zћ42*3 *)b4[jAwG *¬+ _Tx}13GMZA8๵#rpy 74edqS\!ObT4޴L-Xb>4lu./>dwc_U:蕽z3f)Ⱥ]W)v,Ia<hJWwE4c]gO VJJVp`"r.zO6 $ч(1|}D0"f_HI=~\VB0=XqP8˞YPIdOvUKCM2Ja~@OZ BJ̤f@e[-?` G3i %c)oĦֱU0HJ+RB݆ۢўa .pgq4vIOc\,{㻵]A7nO] .yYZf)'6>y,\Kuֲ5Yi_O: YF!mq"7!Dd7G樘>\}x|7*&Nw~aW|.Fgܦ&! {cyMEJf2;%ed t.gIdzNEj0xy`;~r-tJ&_f'X2,coFSLatB1FU^NR0OoݝƻJk fA+ TGxh`R"n*?K-9ŦDNt*BvH\:S\cđj3i#Do6Gx0?ci+Q'hȦ 2D1X:dseU} ke? ܇D|*ٳѹwo 1B81ǐ (P=xchAa؈Оl_[ܭ&p#[u*>5fu|ǶnEZɦ;N('Λfշ9w7M&ÈN?`N `$Eb_TX:P4`mRrn0 CЇ;SLڈ y :Y uhFߪ34z9R㤡QFIA*kfiZ c;њEBu\Lf9`c,L]fR(Y A+OJ4na"r3=(mG""=4\ڗ Ie<2c$*Fv&/Ct荿.ȳb5PO мX*ؙSE1ki\$Ї)D# ]7t%Ap7Zt1[:W S=-hu7#;s&5% ϖfpbXpI 8*40(5 Hkh >L>a.gNF[ +u{N2+N ( gX bxSwYd~(XZ*} w#J[cӫlϨPue: ,C%$Ȕ6|NkٖʋS}1AYm)}fIXjM7QKg\SHj-!C`R_JqNk4Dyyn3(ʐxSY9o:&p",Z"D jKwkUMp,cPic7rSa/4K}S4NE qZ6Mop8H+2UZT;YM >A!c(dwM"ED b_VX,@+t2;PXǻ~yP}|%"}NQ[Ȇh7]!L\WP:IjdV1yy+QIdk¦y$cȋFVJ=+LLvfE* h#s,Xֶ=HX:ޕC5 .E`trYWrJY#s~3]uυNvVͶ2ehZ nbFJ9ԧ||ۇ>dz++5zt0xo\hGlwQ:O_K֙gzAWJ1D@nqq.k%KDY=Ϗ-z=.9zšUQb~pxL(0T7>l!?09ܾXf:̮.7*G Ҭ:Hrs<;ْu'4L 8W$`0Ʊ؝DyȀDkq;zT%i0gW[!rP``Ma٦HE/V|q'g0ShFP/voZmug)aÖ0w7 u0=Gh@hmleR|5 ' W{_ vD!k`bg+;oRݙTvW-8HڶvH p1b o܁ỎF%-!  c0jٿdQ Q ;քRt\&jLg۸ w[xI#x%;6|zJ\t& Zϝi`9)f^Q'fCԪUdIw)ᆵ=`?O)N^KV 8BY]S[%9!B;#,oAb*cTo_4V/?>7uH.dIl`-V~/Q[zp{C1ͤN|}S iDap<g\QISgo8rfZNGE ny4Txҏ:X9|fNb=|+d"WҤ۳D=h[Tn\O|Et9 9?WĝflݐR 5lx s_(DT]|V+ ZBpFZ-aS U+ETa۵yy3=;MEdQ @vεR ~Y,s 3srU{/[;*`Y:eYPoɪe0KÏyezd1㿪50^>]6N;ì|zy]>S:V6W9,D˟ErcglAE;t["C;Z[QT4<OƉ Ƀ@)7PS0<+ `!)ǰ:.,gGu`Xq.,+BlBCFw:^IvOt3zh.sn̾*d89PV K`:B8B)dv7 BՆd{ed 4{9EOP[g.`4vM`AD se]25maտ/ ˙!xƨhw@^۝j=/,p8f |.P>t~ƳRXYd!_aM Q+MBNMDΌϯNF;5 3KᲘ.F(}em8~*"8h)Ii A(0 Y&>Ov<cԤ :iL=Y=\Xn;I}y Y9v08RQ9>'Xs{e_tXڔQݿ:܌|!_~\C>7 ͈{3RSݽxvgbvr+(^ 9$o"Yz(ZZ-n~Bq~o^C|N<GEIcC>PK4PQ2YI$-qg^p>ֈ?z3rX-іWI Ǿaz{rb"MfN&OP$5x "rm94D#EGAY`C70'`|[/RvZ~!1iR;M)~RpJDɷ-Gfn*14u`= jW94kxZrI `azeNMH 9 0w6xuk 3=$ Aq6ģr :TX'sT+h97\g/;8E^qwˋM6^CxOl@w쌓)Dju<~{%?dyRR be_\u\zu1N؀t 9Fַ8c|UpyZG!p }lRRHFoK2BƮWǴax[R6,XtHL"<&# 3nq/EؙrC\Bx)b'?z`U+Dfy(#GC6ijTyGǟɊW峥!ui5~HQj9wx9:$Kj yXùj!"DUfw'J*mPa*GFЧDSF guzXf<j-.̂ ^sLzʃ/^-s}m~ *lt4"=)hmb}q㜔1,2G!yU6uO11mkMcKcnAo>#.[ܮ%|SjTciGҔ}X'{(?k^H1;(F.=LlO^;X{ٷU\JrZF~i_7$Iy(c!A-pWnAWWaA{5r-dl,αb}H{ri3@.a="L8}飭7Sp] f`lx`r,wA;W|6{; O##Ji|t-fU> ؇c];,%ddl48"L9qBbV )^(-"mԋ@GS$Kv3:K9]t*Gp\*iB63-}OŨ(PLnRzcA IOIƛ_+qd-It6WuHD%3)qvcoc/+@snuI_zPnQ;=,37%`(!3sӓO!^ka kzjg&W׌r^M=W\FoB81[h,eYۂyGC_:gZ9~]f$s*'ع.R#O~8V&&VeӇwёOйd)b ,ުތ# AMmJ#;!Amuh.=Ĵh,졁]k=8SWJ6nrWl|9UMT~HiZ̓ ~a'żJ8i~ c.3Dp &Ⱦl%Z`؎n1hiij[g-rT2kk?"^;F>u.ط n8 6cUBhMzp X]-0\wh9&qF+~$%]I"t5s5p6ў0"X^HZALx1[mU/U.DAڻU/5ȖQ(;(qJ>C}7W]Ԑ׶G0116磳n!3ov*}S [l³u&w ަyC ,|ƫG w51_~ M"ΒMao=N!]#VϪ׻ +fZ8aSIgެtFwd9ԍز̐JhN᩽Ɗ)Bos8%e~)}Y0* %Ujy Ůu(FI7?b\kk;Es1;ݜ~"5t+n)[ putj~!Q#ظ ?W_*|ـLn KVf)jmv&Mw`L?YuUj^ յ^)eo;hj%8hsr1\+fɳ6~t[ 1p?c r.CMv:aZPeU9nh^@`OUL@B]hd(gb6G1Ƌ:;#9@$LigPf/2uArz2؄Sb}}Fxk~NoH>6,Z4FU%nAcDu0O QLSdn kD_P!zއV e5SPKi@̳Yu/$ύHn+`*'W Rl_R ›"sI }gϱ]'[Dwc6Wv-U;Q /B({30%ҳ 5e!C&Cox b7DpXGO-B".(g JՕdRstPh*+'ĿV8WhZɔ׃WqlO#D9U o%Să/9k 8O7f@ҍkƠHO_>M zSL=Dٯ#ke [HjoKAJ3yQhce{D|d X¸)ZwĘ h0uHO' mBm^X8K6:fU7*QrQ*Mzo/l<=u&4@rs#F-c:A'H_ SyG.7%ju#JǍ:ě_FAĮDn:Kgţ>VGHQ7=\Ut>M„,G$^_(_\w ,^%):/KĎ RKSr/0P6Is;C ABJ*OHƿy3#Oohn>Vl==m8{BE`!W :]?DG|A6d8L/ʧcEV%Gk:vި{E`8^q*P/L+*fv2TrwU=Bɝ0oHwE("Wl/k긜Fh.Ugö\ς7HdA~ʼ,.v&R w0w >q&"FZGsN-;=C9xyB؝^sՎ ΉI޽ۡPs,ʞ*9X)?*x9S`?9: Pn  x+a2tZGjeZkiYٟc؊Vps޶f!بu"vj{>QG66?FuU 6gL!dVsq+6t兲\ҫ78)!z\;4jCۊY3T%1V6ύv:9 ǒzdo& j R^. Fv_U(U:=Ӷo}K Q/S`P/SW7$Oz KAؾm>@R ~3R`5dpe&,alfsscSPzCrv8Js5i*\. l\ݠ.άUUx3w2)RCV bdp\cGNd{`Hj=Y^Ƥ7p뾮]jflZSa\ I5$hJm犉"{vq7T=]2RMA ˒u?}‰O~4`AnK-4l]qsʮ`P?cGJl"Ҙ#exy~G xR܌Ɨ7SPbo̢Ա \Iт@]o9Gf)pS>\;-p2LN Kظ'@y_ZnXHb  `,_I& N itS>*՘s8e*Vo)8"QZ-C#<LfٯyE5N6H n gy $E\`čs )IuZ>fGHj?wֱ_L*42 =k5LT4NJyzMiTWEvJ\5[A`׃kP6YK?A&g?O OF6Y!WofZT5IpӢK*S_ _AR46{1sƞrپ]$0؜rk=tJϧ>SŘд098ʱf>WQN6[N(꨷BTWjܑdJ]Ph1q!XDd >ᢵ" HQt 6P)po뷢ܪv|"*6NH;Hn,4ғ*fk_VyW\iBm9}!1M>eBџ1I^ >'Ig^5lb-궄Ӥ]~Zf@,e_5NhIR5 DJ[bDߟ9W5f?*٢%nIdvIM6"S7y*"aڔ1h}"C4 IU0.Ɨ #D*2o欬ivSo}̕x|z2m +-nrTݒAԵJߥ/m~rQ?hv Zo.YZ<ު'e*s Zj+:ԣ{E?!Yjܚgȫ8j 8yAZ b{[|'8yԁ%{<)%RL}Tn7wP+W:0 /Q~!8LQ3J3fD3j]F7pm^wCchz/L-yMenxBpiH 5^> du+CGw^wwj05LFU짣1ҍ 2Tx; йNCqa˕cXfJPfMGr2VvA엁eG)^wB2"VYxnx5F %+w-}dx\`]- .=hv>Md}bK3aG/Ƞ~1cpO?U"V(l$+澮bmʛ&T̆m+-Cd!}ť2v-ԟ@qo^ꪂLVoW< eΠQ(O1kgAӝIæHmXˤE ǫdqK6f՞igVHT[0)?Ebɑz<qS%pw +G z{&ݐ򿐢;Ћ jOb,xV$\iTV5b~ξ)R5}XiR BѧƼ]RJrR+7#e8g nb[ŀȝ?h3)x_s%J?oZ0)7gEFe4μ=))?Ji |+ETTd,!tg^Mӡu+5+;@fKG4CΟ+n7bs}@!0u6 r;%h5 ޅ;Υf x'3xH!g&yM-!aW{ (Pˀ)r}]QMDR}we3W! Cg{mo@{2 5c_8mƹ#⠤~SM/YtpcY9hm>-mpB=f3JE$ljE0jg߿N:A;V? ;6x{lXJo#_uSBb=9y1?jۻ+\՝|YK u'j#_FH4$h STOX7qXI'd+~i~zLm{%634=kQgruIw\gm>^q%#ˢY(˷[6铦n(dC"ʡОJ~.%Now^~pu9ݪ,'Q3fQآ$>:=#Z;Ep^p7 bZUEU5ՖvevLmNb"!|+. Sˀ w9Ǐgw0n׀ T=lnuH|V>wzЉP:{\LaNs & Ë8ʏ=" Co O^u[U?aFz.jho7/;.Z )лB'1 a}vفaZxwxWdNv8\Xr(' c \ɀKKKm('aTS]8`I9{q:_[[Vr>ҤZY[ɴC9`XV|WqMm#_OxHpY+otx4|نvs<%ĥZLT`rj(,Wd<"M#Lh{0?ћqܗQ NRg-ϣ/'SI9T75kFW'D;JIi@w7PZDSBM7i)?NOJjr[ s:U01b;v3x _XFn=,JH!5~ua+\Uf(P28x\#PDq:\k&yV~5y Z+!m)ov-l@#;gwIK6ls vfpIKf~bUR w稢h^:M%V~WFE)a02*i(gxWFxXuxLEvנL}qX 98 gb)^BA8@(""[B?`2HZ"$3\ټ$и=QeW_,Rô,xhQ_8 #y5$w)Sum"҃M(GְNu P:+z!%w܎ͺӓ.>cwP4cR۷Gx`_ˡ'ҍǤ+S.͹խ$/(V/"c8Ҝ=員N|_"^eϮھǞIRgIM61aA*Il5e}H{,Y@\Kq%2=UD 1sJ)ؓ4$7 B!8aDZ FczƠCxv.[N9k(Frõg|ɿ<&o^۵V23_Mj{N-#DzZ8N,;r"ř XxDP(DD rj'ek!!O+ntid @RL^[Է# acGSj*x|O< sȒl"iᯮu ?i"hr:Z-d4;5qHyʽrF?p+/O3ocHt_dB~z5 z@R#QRTN5dw "ܤZ_hFmL@0ܳjA"c:4"[U r!&a™])XX׹a^^:^+`#Lujh<u[}5Q:.j:s;a@ej /tfpB&Id;9F~aqkvXף8~̛L}ɼΧůB;r2V5bx׻tyG@[TTD XHdL98#cWok.t{{&Bin\QCAw`y 06Ԓ9iYoFpusI_N ]*2!1z5, qMJ9K) h[G0v"c/(Ζ?&Q ZN ;vM|/bN42's.Owai.hF6Wg$eEn VX7le dk>.DWfM͎xr^Ic]l9Tsͧ4 Lފ6{} c.b}D)PX nMtkOJ䋅WT uk#t7n//{g\W]\M=ԓ%-\Ah2A:?@v7~\Ƅi//~Ho ZekM0] \؛ۜU,sW:̣lULP[9sߦ x6axPSKٜHLjY*Qs,йásSiT<зcފ0>܉@хǂU^Spn2poXߏ)? -:{̶|+_n#ԞFN- =_ gFʽ)C-AǽDZq%ٸ}2yWm')= 4!l{&`"E# H.Kz ݦA%ӘSqG4ZP=vnUnVy&؟6u L-eq<όM1!bݪ' I  hMF(էb ~vѤ'GStrju ]h]7T|1TW8!痕sPG8p!c g--Xc+珡B%=Wh#VGfn&uIh|Jv&B-WMBG[8rp~1c{}t䀖A:)AǏ N*jֆ0,? ]WWE' .aZq7lJbY!/#x$˓Z\ !yNGf9mQ2`HiĽӉƸ=`࿻ԅ)M٘x^ xU[F؟Tn4ʺ|^Uv u>C:E=cCEBp  b־=`Ky<[8M8_?F>8Ba{I&]Zx&5iqDzF e&E()eLEž_Oy; 4GcN0+OLRΰ>DB7M<_~FIt؃C@ӥ\Y,֕pa"+[n`=cI\X0}dާW8mѯԗ12Bd #'%։wϏܔޣvuEOZ< 4IJ84%;|vV݈geo2g^NQ^b]UsE Fc?MьD 50|]&5c(R# O0D!}!P_v[!('>c+j{iʋSw˓R(R|[T[L a`䄂P~Kw~OG 6ԈF'q&bs23t笗mٙ-c҈;<3|R<mIvUքnmqlm^/@Ze\EwhLe1n8ױx]q9f>1дd@xk>>wN xF OCW4ϫ% gӰSd t 'ڿG_vBӦc̑._.uU,3K[^oz~8dŤY2,J~Ҵe//cIlPE>W?pپX?ZFRv"KU/iUML%.Uya.ԩn ?"-oEyd-dx/"A$SI(p KxVXӼ{x| TQoGΚuzg]&; 'c^0 v@^}~8?6Ꮘ% a귞"#_.V<%.xSV"G 6ȇi.R5Pl;[SYXg29peoyuc2lqݫPd]BpyU3ph#Ƽ(AWۮf؃ʳߒK"L2_OÔSԂo/rots"r :[]>IEQ3@GA*'!nG+М{$vj Rj}NH'1bhA G\4vH3-e*z!45]a~ |-g%ƶ=zf8obpۦrL43sF!r/#x&rSSmlLМ [gjFlgEkljp9 tPnQіZT0eI%BYzEr0& ]}eѫͬ@Ylc0qͣL3Ey15>Ҧ#-VU"|j;\,7@n/FQ yye=V07ջ)Eކ ,֤SbSyl?mL_tK,o,XlwHE>b߄ozI f۟.׻4qwfՑ^-PT7jm?60!+",p>0>nA$fTpeAsYBC5D?{6ݾm;bL;U"Q< piχ 1F# \߼n{պ=.Pp /EJMC.^,ݿyNs4L=0a|$[A*`:#t8ifUZ$̔jpH//B$Uf d*v_)s<87 LZ7CL!Ӊm3z> $XJV9@4A UB* $@ ;ƩP_Je>Bp,dӉ'|eD`AM Ax1¿ZH;oE~t2cɪ(\t\pjz&|TDrn%H#e%囝G|@4=sWPXcys9]Vef{K%Kr#zyޕY;c-[0N#])t7/4t%UiDTi]_A^&%$\fXFU|6 2' tm,HOurf9_4HLno |q̕۞ lX &DY=L,|gq#"wP8V&QՖĖ]ҲgG[;C@JL൓hcgIꊮ;C@z};}|$a@e!ʁ~¿X_o(3UEZ ^P1r_U6)b6 zdU<wqIC>)ǼRڐø#n)ؔiXd; m˅#/=UoeKuFOpo!;6e1+h=CυP;-s#onc]SlmH ty2畺Uc^Bxc +dUfxV<UίJ ϶y_7T@nFX>ҋk7Fל}5܅Ϊ:OҐKZF꬀ɀPȥi.'tFK㼬" oj˜+Y Dz\hh5| ,4͡5bN<\r;ư >E/ "[sEFf9<[8o\8HY^mC {i]a8F?헷7D#tϿ/4]MUb#9}ܐD}ċ!5/}⯅&=Db AU *_<h;hcʯC:9!"Rt6%\ʴ'ơQ:<_3\e*OFɢ\' )+!&Kk꺻ƥME 99C&Nc *jjds\q5T=|myv!$#58u`G >X*{(ɺ|:|.%kЭ-R*?_ )1#j!ֳY䲥N7 N=eȒ`2Ѳ(93! E/k9Q_P:InRE$(ǃ i1;4!3W,M\B89reF:LfB.l:u0)T4ep̅Jĸjwa{T/_Voe/x Fx ?=mHnzF-7A$:Vn:X9]*QڏN?"W KfW;RozΥC? ܪ5>@h|N!Q;Sstoԇ[@( GՇPSgcQWnT-W{šZ\aa Ĺ W[Apf]-[ElvH=Sah f.p2:I~b9DR2hݡЂ'OFX5֞,7D".0ѽ*S47 li:^p,bPzRvaП_$Q?Q<Υp*6* a*|{t>tepK yå*x,C驌/!1 7IJQhB/SN@߿o\0͞y*Y.6 >z]ɂ&LߎbM+͇Mx>V7ϲqAx*DKR-#? ZAYak3J#@=~s J9e#Oie>;+J\~;ӱcMOu)| ڷWrک 8Gx~)w@Zm`"HSDwd-+vzP;e.?9Lp`P}'QΎAL󈦺T{iL9%!!ьZjiWOa&%׸Y$ -ݨ1zΐUJNZ4(aZ[];قQT2G&L A<7tu/ 'bKf'Zv.Jd{Z?ic)0< ^\du J1拃ږ]r= HaN{,I_%<(ir xW!7hwsF>O< Q{l] S%59,IC jW¾gl%7D -{|mš?eԡ$̄=|}wcUT>oOPciGiјA3L5[]AA]Jds<3*| L= j(9; PYq`h^IaNքOE\mןqY .2I^ F,r'J[9[OEPox Pw鵖A~9 U~fǗNu0,{9jvUvݯh p32CXСRuk:FȠ|ΈGPIܛovjh5h)1=tsN~H{!E<2xּнVR;vRegٍ)t.ittiU樂R2/8vR=JN DHmwcW L= c֥t#ͩc3nom9ɏQ#0A9*$49?_9=]KjޡvUBZ qSa~W2.+^lMN8{vwhH %r#HÚtizqB{rt(spk?WIUA8ίFXX$H5R+J帴yfu6Tag`oF*5-őpeXWT7'$IAtTٽr8ЫG PqH{5W$aNF#}AkO}S@;  JǤ/k񙆫A8R0J~+EFVdvPW|,Zmm/v;hwDC m@r 0; p> kHs9x;`IIEcx rP'GPrc NFL't=yeMr6w1:&`.3ލ r$>@I ;gۜ])#5_ҕySLV5.Y \MJmxD?ܳ3"y0藑*ͦ3k:i̵r6,/c#y[f^`*#W[wcglTWP^d{%9u͔ 㿮G%Ixl c7h壸2J;xl@#Ӫ8oz.9{ 8$긲+{BH+ Q)I+l*I&^lo,tYm/(=n24KF^8 c,}f7_OqBŔ嫷B4mn)=,Zom^•%)8U)_}(GkE*Mڤr8:c/D$Ƒ? zMŸ5 +s7t }lE"Oى<:ٱj;O*}om(v.liTh?*3iqpoO*=M| Ɋ7! 7,^zX Il+iBunm0x#4P!/^Wk Ho{u{7ny=v(<s^F"^Q+|hv\AmwiFqX|]Z:!"P62uA䮺Hٛ(b 44]@?z8s?eKRPbFqmp\˭:N^/bxsq|Ԓ]{0%Q0jGn0Ʀ"<+"#bWLGoWG&M 6I8 IVm?yzMO!<ʶUFmbwFn?[;oK3_{djxYWq條+QrഖQYZÐ~G+C0`9b47{orbnR5-bc5.rqMD ܘti-Z3\8Bήzz#t@ a؈JŶ.LBT`[/TXw U66[uNG{ѷ|g75ЁFKn_ V~S\. FKY@zӷ./YB50@+h7 tIsvHf~F xMR ' z'zgIQFD_7ź] uT6GO}6 ϖ G7كpwiU2۝BU[1eH$֪W ,dR'v$(!3] m9o\[EQGnWy|79"9­SCF/\Ar|/3:@7(O8M%PX["L`ık-12k# dy$Gl4zM ! ,PܬAԯtNJT:ٹe z9T  pl>qk8k4,Ž<3, )SViӉwGX${yQFֱ?<20H^Ϭ0mC8q>#|XTg&a]xY$xK7}& T6Ln1ģ펧f b˾fCKU,㋛gVx'yER--sYio`tzt=Ӏ[aIWWFy=[WOX%4lG7A'+`T]dZ20lTe"2-߆R M:$S|T57ǖ۶ls7\ uqhzRnNd:ҳ6{ @˔rϡf0څ@ ZDw_ jŬfM#.'K To?k3>M 횁̥D^ni4¹ŀIzρkqQ+<2eO˒7RXV#WϮ9f\Tc٫>29 όZ|k+(䦮4 <'vx5+WI Bޑ$oOx5t;# _&}nݤ7K7qyɵ-ZJ ȆJ֜\=h"T9橝 Vxabm Ϊm?GWmGOs\Lʕ B8`Ndi$: !6-\. h@o uQ.}+ 1]* w F0T7IN)&]4s8(7 Vw-25p"'F` V{h Y!mSႇůno]w@%\pfn@O^U/&z%lKqY8"2lOkhIƟwxOQxD/ (>iA]GCU W;e @& %W(|tOj e ;$,տ&Pn_rzشqS͘JfGeʽ~;6~PM)٣{fkP]Z A2@gN}TЭ|Dc\խ [Q˓oM2@W%i IݭXwHP (4-N4 :-N00_Sk-Xg05$NboZ'Ck`/.pS(Ejr;TxgH@oYJ;^d!ɅZ*f]k0ئoR)I*~.,1]yCRTGYߟ) PW09XANt0{\_M 8Pyvm2,~!~5O|*zed)?oR1# jq`!(ᝤV@MO`H  ꝥfPD,]1$q19-|ܜhd޻D׀cNhM tyF#:'Ha&FwݮBAv/\_VB# la_@wjq!4L B-lQ0k4CkʢuS^ϸ ӳ)Dؙɮg7A9߁OG I**C,ެ᫺=+@ɘ>A~ L 6:f߻(:fQğYէH5cD]@X4{"&88^$O͆깟;λm!Nq)Qhy"IAǏ*^ lVz4-ʃLU=#vh TL 瘁K .m"1 $Z/ ڥ;$ HQ2wbIʔX~-ӠykАFAY D<]z+gFK :3X5APىcv?RfɤOZ0v-2e#:2Pj$+.# Hg6\Q"Ng|sphO;ST[t @ؙ8V &beo%thF d:L?cBGA.IuhƟ.S j=ޓ +r3M$4h|_lg;%ĺVHLg~罧Dd`ZW2D,Y5E<,3buabФWٔZSavh tu%^SQOnOMuvz6?GՍfj"*> Ɨ|Q 03mAiZ€~\@|ƞxϫ @`$+5zqƧ; o {lcN;tdG`!͛f9(C㌚} w/bqhzۢFy۝[S+JjB0K?- ;qʒc"UP{cQ#س8N:9zL?J`@mX%^@HAܧÜS*`F}}bfrUH1w|- -Sex0kc㮚\NAȑ{7E2B@6w/Zƫ}"yO͛%+G!ԐfɬTmvD0C;XLog+ƛ)d ƛ`JdNز7}Jp}MM>_u'QIe khC[5ime'GKx;гp_ʩťU'rAbOl+og"d}%wY al91Rj!1d Xa~?Ǝ9]tv-n%ȉmb4м'tv$|,ɻ\/ AZ6t&xUG`YĔl4 R^Jvw"ªiN_*iJ.`!n[U=~>V`gvHg{'6J$=z.`/REiA[CuK;K_=&Ӫ]e(>>VF-ӃK$|FI]ߊ-irzfkw ݫt hjj. lSB ty~<4B_ c*\=n͎,!.-PxgMv%Q肾RQϒ8 @چ`16bX~qk jT<82CqiVj`q:WUh1j+npg6.YJUP dc0f"eg9ndtHY0 h7*wjSQUD%3JE&r ,/U+]S^1lSr [j?6`Rt1+I7,۹ЊUE^r==m}ewd})EyR \qT]=FD!eyղ7zWGkYxČgPmq͏߱b:'xZ-kpJI@7N²E/R2y}U1қ}]%9o(p3+ p,8{ ,Behq'Cq\>蒁SxiF'(q>Ph#*TF|s߽DK%хL?#gue:5f>q.a[hO1ⶲaл`SG\u7Ik=71J:Ԅ5Koz=S|ȾK@y&AwY\pfT:7,ڈ;];$L+t,C-Sp@喒j _Jmzr fF^Z?{LXpޜ{T*\l{'+Q A{e.i淘 7!>OKV:DՍ3ҖU^ q0znre{ ߗNY\L fyJA[l4 }k=(.ӎ;K߂tV[L1C%K'8OjK_ߴ$^mȮ*J"q)ZOj_OHf#J0&5o~Q:rzl]f! t`& JDC~xp(0|ݘ=dxFɾ5b\2FU:Y@X^g`nxnS\tG'"aY"j~7.Ϊ@Pskοk[]7]isW͹yQ<WѴ3Zq^tهӢp+w^CC8*`72ߕP*-φ"*iw M˻ 8*o@.z}d51y'o^O _0yVtjWXhky!7Av;3_(bI^{>ni{Ƃ Yt&|-BU'rhjh>N;Mj%!iٛPꢦeR_}ߪGzg)(FKP>{%C0ډq Z(DKkz8ޔܣBcM,sEdmI *-b {W" QD<[W~]䦴C ˛[frꚧ_*E.>Fd;pLq7YOf=^a]2يeY7Y"]~#å`VcO~[ 0xv "blA? =< ?9lq#k50$Ϥ%U_ G_;oL#Lvv쥙B)Ԣ/ v Nr "h XIN_ϢѶfgf${)Ma%Kk Y$9-*["Sez^RH[l1}Nw42Wkψs*V6J;d?̂ pF=U_䃓Ofw90bE#LYb*X9r+^.+bO季+R],;kQHr 2>f5FdF AR& 3=g{0 "a_2@,md7|-T!?m:c31,+/Oa$dn޾w_M~`Z< (E,#,0'ʕ?1Ztxc֪V@dUҡ'J kȖ.筰=R,oCK=\ _ V!t:AUWU³ߔMwvtm&pJbyH 23N5=9}+M5J<u +Pfq^ι8:͎#2L#x33 Q␊XpRyw08; Z//K]~) \aSI,LGur*t\1Xұz%A~K]hhKX0V}Ny ZZ9{[c/ '>$LT.I;'/u%ކXZibB|^/'L< nm c;i~6I^[|ML!u4Zb3nڞKb&=FcJ)@\8Z?i2BӭV0T&N֠=5hX0aTؿ$8ҽ\ ݙǛmQuYU )5j@J$=`_h9%7FpUy3e<*Hܗ $w2ZKmJ३hT.!3;m||. 5eyP!A[=@4EUpŗ#@`p͖ f3 5jY F&m,ڃƬXV0hK]w|1up"/o2ڣ{ٻ渍.j0^P|fճ$cmk,Z0YV %kٔ[<|ã3b=?7P9ԉ9dyQwQO;d9cprEnt)vQUO©CYRԹG@zEzRKr 8 zA`-FtR7>`:v`[tT@}Ҫl)#RrK 9kO+w< 5  Eiϱ?><FJCw>"StRcz}LfHCuqL| MΗ3kJ%ߦHiGgSMX'#MX " GUBwھ g?=;mMf.:QEk> )6Q^}џT'mf6fP: Nuu Z>{ is/|?l;hDŪK}qɣkIзg'mr)Z3G4:?זmWe$ L4Ey^qϚA 8q5c ;'g=4$&Pd=vw;8#L.1B{: ,k#hɇoq -[t.δqQ}J667])̢tKNzEM_ܐ K#E9`vʼn)|D&K*'}jL,xplނ9qz+7뷈 K:KӦ A淲UfƲad~XaG4p7Qڟ\<퓭³4|h=޲~l/  نc7zG fiK1ar ʪ) 2tnΗH"|'2fp4풧Y\2'27e8 o'SHZ7EDhaU jna݄#^u_ dt@l3KSXx.O?A0oH/A;VV`,((v!x V[b/dsVNЙ Oi<4KavZ2ꜮW˷%QfI XBl6 U 5-) ތEF.Q0)8 ;S/ R矦#]/r|w3o ZdLw7nFF^+}: ?d>],pYKZ{4kH_0=blaGM|V*0\AkX *r}ԼAvgҨ[*:Gݘ:EKoüm;%9 C5#vΈ^x8kT w)~ `M̆D )Y-UFZ@oUE@ciWFPWKZaE :82_{WOi;scc 7~M7QPy4!<'@`Mиf4G+% ׈ w .@7!gM1gK@Yg4;8beuDCf'253">EA7.{|8F|Zc[ HnQm3mG^NUyFhiXf@n3+ +7S%*Lx D=Nɑg $L"x {Y:XkLɥc \]7P=7j*B|q΅Hkϖ!\TtKy]4:;ad uYώ8FSكS;d C߰uLQJJL^/y |_WE^h\B$nZl7UlOM(u-W^z<@ x3@LjG #RG;6 TWVXW׎T+6@3aKv4w[Tp1z.G\N3h r`  EvGpaIhZ?/ѦV=ѾQ!MJ4E0%%7MB`}V೻I@?7vQ}3\ljd pz%auH0tdI#ĩ$ٟxHL "lI=2x$zדnSii|a_ӭ-8HRwnyisNfwuA iA*RuSkZZ,> Rqg#.di % Uև9g/NrM0d!Q2 ЊHјJfG=-;fԑw>q|(cFf~S6:30B~z:} L<4J;.U8]mpa~g@A ;Oy:*b9@BLٵ)I&㤔3b7E9gktChUb%1a1A\t??H*ML;KsKM`:[:})+uBGDwJIT&'yW ]gBG3۫M/vz7R9T= ҟ`qHN*z#ZЅbuϑ^t)p!^)H N ݜ%>AQuf:n!8*zO.E٤f=?Ғ x-`)qQ)gKSf|~)/;gݫQ d,}ލ> 3-QO(3^ [Hh_f`Ij-ךOJC}!PY %7\,8罙Oх]8_5%ₓ}jD!Φ$K_Rs{ʜ8>HoM]kO7SUSX Fol|0?%8'ujV(4~ EhٟcO HnXFHrs6v0cqn L&1#mIWgX1Hؤ3|tzjE[v%[sכQ>:bXSn`Qx˻woSa ةW6(+ʑojset$ʴdzzD<[x?Np'7f]4FN=SS#lKtVEc6}9 HFْpP[K\tZv c+>PlA_hܱ!Yz8 dþN}y[~GNw`svv |H_8s͞ŅStC_Нxy{P܉d [ZES3z\RZy N3[#vp׮ }l+#~AoȊrݜɌ7uH+<A ,\N"n$l6<#OP/1B4=_fVL'V\FN&JF@|&O%'|pҎ|\EflCUdepqM7Q, >X~>B{!&ezaT2ǥLsTw0 l!Zn su@8u7<\"<.Z:/bzߏ<)߃X7ټ(>Y(SݾSj 0>KJ7E:aE_ocNLUHb; ́il$Rį3+C}%cҮtG! UÅʯFC0sbm{O\N&&L wt.#~=+K&qtD {*CDk4 !c4LhaGJ匷.\}0ygj+shX_8/EyWqg,-E暛@NÍ&oaabowXWp=IHJCn~j+{>sC,dgYB~eHծY4:Xa&~_y]hYGm۲Ij}bƭy 8״QISXsǵV8Ȥ \'na.ez5X=LY cqU&dJ?8-k{, h,# 4n] "n1|8YM d$ŠzD艺&} ~3&PDbKEHLaX0ywVƵ4/f5ѨPIhhA xSP56[k^x½A{stjx6.vq KMexQ5%w0'ew!L+&GG#:mdkN1Iwg |4c<[?9зxvn\Z [:78B:kgoTp(&rlj9v/,0͛Qrcq /mX`"߼>9q&kB#q/OcZ^ $.9E ΫvO$XoD 7Q0 %YLY3iWC:<ᎂ(|ӿ22AY)-۾-z̝Bz@X*vM,d̓I}und46}{h6O|ů1ԽońWf=!7r]{R96Б $%gdljG|ݧ3~^DLWo1Zy+VCTjL?xdeAHiP \ƀz#A:WnΆWv̛LQ9=>zNB̀:ֿ)z+Aבh7p/ѵ8X0}mJWaHd\hLNv.C0*bEclaߝC8A{WXAYzhx¶ULEq砧-0C.EBӛcVf#޵tI*Kڋ*pMu^XQ [nSڵ9 झ1%sJGUJ"5 E7 )n|#b"CֱQ'`Xظ$sIc-nh99BȃL% |HΤ=gL<;N)KAHf>e+u0G$Hw8y\Y GBrxҔ]fd*GjXmW1ezdOkr/y8@vϬr;zPqV̒ n Z4괡tKg&Q*2zWxwۣ fPq)}wηmmjS?әb"__Zsi]\:/ %0,XHZb[%=~l%*RNvV8iL4]ܶYf9WeeNaU{":b.6TvBl#nG˞(qO4VO?fM|ם?Y*{ʒ{v:?+cIE0,R1:WGMQ 5oE w;%%1DPu9,IYUo#V${H}>UhdlHJuX ZT~v%QMt&E[%ZS#F8ҐhG}m `9N5鰼Nf^ʚʮ#e >.rTGknyp@[m7Ht) ؐP2jD\@VVԾ |q`2`_/:`"+;.}.z܋% x>UXER[wғa۠c(gu0g249tx_ێzO}y%^>Dϩ"K f{/c /ld5b-R -eG9 ÉKoZB'MDn(p4(f /UqoJЩE[ ֳ a(N⨮5Q"* &6dNI3SF?T >߻Htk:37Ǧ@ײ!h:TS%Z ,@,V 0]K_-X4m/>3&v:熢_L8^/(]DIY75|-UБ'bW, r ,O33#mj@(~7Ns'OOo*uFK)h'+K7<9S؎؟: *!w%MUD.%׭{]{j 6 D#{.}tEd=΁?)$ҳ R=VؔqIՀ6`xUkRNVAib~Zߛ22_daD1Matnbޏu<Sst;`ﱒr[/4H̓ S6[H-t3̎TX-_, ||><;k1y`И5E ..(iJo1(𰤝EJe򫺽DKUrOIb$W4+qدE&>~+UxBو‰΀*>8UjаKc'rnu+j٢W54M n6y-I @ V"k&6u ZLd{ 8nG2ti i3>D xd39x׭CutKl'/}\ ]:Y~GӞ+Jy8-=Cmfx< .L΅5~K#YQb%sUF#G_7Do>Kï1?m(paϊTkċ D z^ K3zl|n",!^F).;Z\H՘3yLRPvK>vf9P =]t, Mw2-?q'Tv+S!Ss E5ǚ`:hovH b@gjzNԟtLLr%]# XW԰*4Y=^pۗBw&@qj͎e$_s" avi)Z>\ah,l1=o8*.Qާ'*, %Ү|r*8`D,݄2%1e-A88OvQpZS3W>ҀBx'y˹ATBnk誏&i7OK@<|alk2jygU\R6Fdk DESC{ͳ체*9[od/놮-PI;O _~ѤN@IyZŒFMGE뺪?'㟱/pl އ\F2ΜB:hM [U2; WK=1w]LbDRqM|]f¸>2l֫D(ͩ@6>c3LD.2Ω^Ӏ9GO.֊/̄ið*6cmd"t5e`!TIp>ޠKP~Ul (iXb#W)2J)$BݨM5%ҷ]̶͌$y kơG!KMd;.u-C2ja*>8)\ ' 亩% sIL}梘ǐ̪x2'GP v  86(^W=w#>Ǭ%5'Pˤxw'&LULo > B I-.ĭa>vrX˕&ѝW7,-tiM20 [y!*}JċQ8(*X aBp %<93YDY Gb8G҉=6Vh`\]vd]TXn(Y8] (% ILJXgj)| Bfy^_K;4EI(6spW2}!0žӗ&prRչ(*o)?E.#}#ToThN0]!ƚSUT`Iu`pUKA &bfL]L"ZgKQfo2h/(@އaf8 =EJSϼekHH%t=? )uMш (|÷r[SBWOdZ&\7 T{tsND5#4.%.N`"z~aB]ue/ ,c=\"io2:8e=\QN^r!AgI;1Or6/W@HX<¦HzdCWܒPm iII>uXg :|f nF/΄.in8C?gٔZ\4[{a:< 䫔m ޥRT܂gU4׉4|tt<(ȩF>vb9,ys`,I˙HGLB02^}P,G6׈ch84EMbD1I_~} }8n5{1 imÛ֍2*T{m7@ƌMA-[bFטiIu2;$HU5p<{F ?:#)nG7GMLDDFvx@K\TNR$;Ҍ _ax~EFұE|&ᘏ'n8%TGF`.-6`}7wR,jtr↓BIDFH~KgDMiFC]b$GPƈG.Dd||ASgf~SKьՍwuC|ac4ihīhێ>߁ c먑lҾ}ƻkꏒˆ4: HV/Xǹѻ*T/?`9}E+0![[ U}y٢gJLuy XgIu-AwC^o:>C!1c rD6ljYaATwE-5+;*BZyz|ƯO=~ O͢ʠ02H`2Ԡ^gԻPӚ1 x*l}4>fC8]]FȜm.8qi;I܈~=ϙ 7Ϸ\8[#;j^Ih YGǕ Tct#{(3R23ۗ֍´[x0!U0taWt(j+pۘ3n~RZyOizا@6jF?Wb52+Y9qыvN tLbuC̍eug۬e <\nAv?0L izq6vۃ ~ݾXD[1hUaM<l56i}kѧ߬_UV"܍BvOږ/r `R{~[D {tTSVf8| JsD+J{^@ PRyz;l\ Sb)Ƅ~ҥKPᵱRۖ{W,җ)wlM-Ơc5kQ.G՚v.2ܐZH鬬WV~r䝆)@ ~5:ujLd|P\W@q]kVc_ׇ;lA^<0L\6,mEV FpvOZm^) >GQYy3V&;p6U.~^t!l4qAΒŁyqDh78EتEZH.qHEW7 TAim-Imo]ܹ+*e6q<A}=ӍJ~v !Qr$D;lSn>Զuk#q~UM aX J{Pq~i:ƀ~CV_XUVtL"r~@˒4<Fj.H_ehGn3z"hyo*0eN5|ᎠW4&B wOC1O1f%QwՋtS ̓w{{pW XȿfgM`C@L o"r+9_`.x ԗ~پA!$a,w&a;/Ϻmɯ}qm1R19MYǶ$}i?X_h=(T-ZVzfty3T-~֦_TḇTM'n8! 7Dw'點mMu#r{hRm+;H Ʀ"8,dd]tfB<:M $#((Ӫ= H!P\9S{i.y q E~kO CF+'ivو;G2𯄟 +|LdD /u҃@ h+y=&s]ˆ5}o9^JU[&>TL&K I{Bdw$prm q5jPȐ~';^|HlJܜ,uQ[8jͫ-k͛7aPg@uҶbx OYNIdHɫ2`XhtȩQvk".c0GN`3?es)ut2q8+Ŗ̤_G]4.3N }t`@vŀm,$>Sb36 H  I2'ѿ$?7&ʨO-sL^c)?MUĔ_* .K0EPqOX` F5P?[J٥8q0gI: pɓ&4r$>[lwzX 0Yѐ'@ߪEMHm0 PJ_xy-2R(@.h'0ڛGw SiTФjxf'wV>eA# SX~hwJbU^{Eu1mB8VÆw{3MAFT/a@RU=%jY$? AF+M4ƘCY`x W.os͍1m]&k#gk{^cYM3 X ? ԫLg1(Ҫ?uُ\nyiJT$*GY"c~ A n'ݬ/1BNzB21u <˛ J8yJvlQoWNj`TuNz_+1u Pu/ެ;6Q ͸XNNp1[6Ko~Fߟ惠F ɱFpEUG/s֤:Rg^͋QGMa&7r`yOl*wo D3N,ƦQ` Ԕ0  2|6r<-/U=Q5|Y_iL;ǽFm{xk]f`3v\,*f$l7M;G'9b3T}pc =e 1NI3 UQo(i+{-T7Vp=jGFTiR$k7Ip,G>d&Il0OVSWKPd_|%dﮢCopsevϯ/5Yw1r큳/}w utH ̇$Re[l;;:Q:NV烡y>U@pp*3A#54m-" |ekc'u+J,hzјkY í6V#\dI8QS;BS5UK8M+IH>."Ðceus@h C|,ٻ7 P_E~F@j"ߓMC'ZR{E.х 6 0#%|_^kRSX3z\^*Q2b1ȌԡEY}. `(`Gi;O$&]}7'EO/`" 8F\1gaIK; Σ$՞+M,5a;ܞ6Vo쮤 N Av>Q;Bqc7M!90d6 ?bĆ jdST0PYTD64J_4x\~| _ .Տ"VQ_fSö|sOIFUϯӝIBK=r\wYwG 9k( ߯)/3D*:˻`:($p&~ӻ gDUaEs%,3<$7AbǾ6kgSWy~nyo^W{lp3mUh ;q6<˾ EHzk:D"I#x:nT 0sӘ,ܧ'qKV,jBH͖h$ԭ_b}p1DL\I0,i(&ucxH*4: #a&?J̀+z1TYT!S5 c1B LUB \sx47'6JJ]2I'/򳘟G!ӫzuDޞ?ړ\djO [OD >VX-Jވ}/)?!2+>yV(E*d( i[z$qwQG0ڄæzcRQ{}R- i'lcW0(7eGY hhIiѴLX:kpױV!mdxa.G (SN, (?'< pLZy霽!ok4Ղlƙў%-[c-4lB>%Y8;O<)$D†뭿=}BPLDV{QI\V1> *Etι/ `ڍx#N돜FOn T䜓"{cϷKBKhmya[^yT͠+dTX`SN9L0ЁF2\Gs=i'1jL.݁+v++Xr#>OS0l7h̨urRDzKq©vQu̸}XՔړU",vA/nߟdߒ7 ¼,Ę0J=Se4a N8H5xyTL<XKcwG 9b. $˲SO¦K*@mKV4INOl#=X2D1t+b5q3`3+rzpįib D]Vλ$ ݩNjњRUh)L؇UOٸ猇 )Vƛc*x`u}*l=o *d̖R*Be(7a?_!6r;PLXEĶr{fw2>lIs!u'DtQG?{G (z 6.K채_O=°^BSO%LP y#P>Y3 )Agt('ꕩYO:ۮ0R_L=;ؔIzm:n.5e{5An8WcӒHJ2;LޔL+BQA:MCŽ%.i)]Yl~YԜ= q#T[mXI foxJIR13+܊:cɼ4yF;nBblIի7{I ?Y`]) \z!TN}MG>Lj.RG BI]͞OcKW,x$řdW/C45TIB)wB]|ezDs!١JfFX= ?ٟ}1;|H)DD~g"mg>%Õ3֔v!,SU'XQ]}lё**8E8LQ̀}iAP1DPni4[8잀*#NakQ\w)d%Yէw1M4W͂lLS&2gEB:YA׾:o=a_Ն:댉1g.!(Ȫ\6zu]K|tY  [ϰhdYk jwIQcˇ+7| 8, VpdS_ޮl#ijZX" ܺkeů$E?7?LE wRH5:T=BY&TRZLƶW,Js| H'nM\S;ƅ&J8,H;N :2cckm[eq3+vir\~I#Th-r FG1j ۼR~{1qS-:~m/H -;;2\ْul9@PC(h*--y-Mb'8.NqH$y&7%F:!0ATK <٨K ᄮRVZH[ˋ:Q;ўiI)*p(P<6@y&$<+;E"&TE$T6<|ȝ|Cq ]v}kG_)x<:?8r)K& GYMSt?K^́{R,6!uv*B_gZ:pQ-<8 wMe{f95,&pRϞL^tzڜ47VP#Hne#ᤑSEsxL=K4Lڲ 9/ߐ"qI lXߏ+hWL*c ڹŘj,KY';(`ZΎv,PvsW;j 7hGQ<þ7dWT>ntiy?il&"a $= ?Y;l5;lrRmiq>"*ߤ@FNE-`לUQƋ(=ґVf\..G A{OBv>|.$ cö6 w|i,bw+DOe4}ell).gW֬g߻BqT $`hI%k9) ݔRo)+!!)b_/4&B;7dy2߰ۢ#팄VKfܘ @]vyۅYxS<)wk~2Go"KM)s L7:lxVԮWB Y{Iٖ"Fc烴._?JM W-{Lu|.TabNE ?ap.NU \FNk3=!6IMz]gaѺG{zA I V8/x#E>ϻͅ1RΠ{o v2QÙ5?y[j[cOiGnU2)jR~.plvۚ%!>y||5?z>b2 WBP%3D;R_ |xMU!B=֜|6֋{ۊ6ןūPF)h@+NKi;t&sĻNyĦ0̱v~j (4G͛V! h2? P]}$Hrucvvd?)ΐ-$.^ ֐Es\)t>Kȥvӱ'h1|OFV\@a^C&~C ЊzdI5 } 3hI5<4CɰQ@dz.o*Ru"%$q+mW8㺸`S$?ws$/|wT"dɹ)T+F <'Yj_~q"Mmn|.]>)_.qH&S8ߦAt5YC ,4˹iEmn s,k h=HJ!M9ԶN~4h`l\NY5ES)9) K\$Vw-ξNy,g-Hx`aH M>0TO rK^!ax ;DtȹWOzf~ΥKH%.F_NOwԶS|LY*/1]m^ZCϳE޷\>sgd9Mv|mn9ŗ`shM *xְ7v,Gު}bmyU y˒F4;e~"_BW`g8Shkj#c5=Ǭy ~clnvK|,TX2e;: f*X9y8yf3L?ui3qDb ^;pBO5 Q̨,vfj+~fILLyW3Oےۉ̤n>6B3<|@bSΏ̞$vGW!ZdEikN"׼3[D\ VsÃf ^WTI,+@ZԆCV>hWڻҳ}oBNVKIkmQAcUVhrёU˂'EoO"WƱ="eFTwu'R i_ZVŌB5˰W0/|66Ǫv Z< `QR˷84ۓyL/ 2;' ᵛ\ď]z=ڢmL 씯W aoHa'&k%hՈ?YD0l\oj8ͪ(`c lM"<27T0<[y/;CpEHZcBOVR!@4ta4ŭwT\zc٦5ż1v:Fӌ5_R9sCys\'yp5,a>M_anw^m1+L9qdBakjKw^Bd{gz-UPpxГIwM<1r嶸o%TLG :욁A@{-=&TXehd> koVA8%nqPdv~FyZN0wm8AÌ.K]cgaՓ#]e}zš4H[Ϩx7Bi@6jЃH,V^s&e>&Pfn_[~8Һ7NʯUL[K 'B^*7<̦{olTJaGRBS%\셌_0W 8ث. PN{6KY Z;jiʍ3^&82~%s5 OȝmtK =,.pV\8O-EpO h;XuY&\LøS!ݢz+"'oZ pIcϢAzDNo/xk>B-غf}ktA^^aSaoY7Bg^=RMKD=9A췽)E8JLr51 u- B5POP(B͟sI[M?c{ߪQI "+9v.4*耰ViΙnp kTd(+\}?[qÝYU\uIC;f[<͑73mJƢ,w{ ,\/~ /VQ/M/ι* Hspx\Qyl qM`cQi;O,R 0iPfD7w w|#KkյȗkTkC]Iju: )0T?kn}TN4)7~=~A&պG dW0_B8cKx_?Jyr7'p!>pDL6߾05c|`ӕ)>yJ1FP":aT6elK|BXK-"*Tayצ<4G]($ };p@>[Ugnݘ6<7eZ!E_w|nfh$cڍ|urA0.s;et",?021;Y7K!XfСy2R $$^MP\f|G2akAVzu/*ņR w5tIߒ!I~%TZ0F{PM"+MOΧyё8侕eBn=ϟE սZJVǠMt*SjQ~% ?cD>Od gM\Z. OᭇS3~:r4[&bS22!^?I+#/ i7\@?tC;⡦8~;`XS4 %u3uJxp:bJ*p2v4yW{*fKF Y^^?)BOrzGZ 6ҿxFB`$eSX4? PT% \F\BؽSN*^d֨Zng8gU%ʹB@JZWl)'zRX l[ڍ(G>+7S{äKąڦu3\7-] |AV2Imp?~߃SUa0unYH߰eV9?fkR+Kh;k n›k-[?n)o JE>(2+즒Rht Lfp5YСe%U0_5/cPC*@[9SwvQwzagN~XcyޣkdA{ᙠ3sf> Y&R`wPZ2R7aQv/*! nL J㪝[BƠTVBZ[DդS2 )LӼ[|dI5J*R\N8}ˀk  ^V܌>b K3jo%lGhSI%݉G-"M[^Rq}vl=ʉZ2]vi#0@SbإP_~WB.Őb;;ٿ}NRy. W7߮A2q%ۭ_S$he0lX})3^|Ro"RϪ/-UFdܳ q:@՗nK51@fuW>e]|"khI!rWNo9`J$K':3$q&i ֖ {$~7@ $DGs47kG"pI Ѐ4ƞ"9W#3䰝T"JI =N]7?pr<#@T9OA\FLj*:Tڵ^o"=<:t g F3)mއ˰}'fH6a3bG2|!3;'4 N׺(!VCZ;=n!Fq~R.Y󧜆ѦBb * ōAYē9~&wLjlEsw{hr0Ʈ/6:)ZouʇV+ 8`hnRlHbnOenPb)if718t0\`/O$eẖ2$LLZP#)d(IJ>iolљ ́ ]dudz5uc^ǡ|;kGS[*M&!?i[4P~)yhq{lS qr-dcJhzSUsQ>Vּs9 ܂GBKץ<-p|Mvc%tȤM<kCpSIt 7$v97ŁO/G3U>M j<3|M蚭 "SO4K.k03薭7f b>I)֞hTQ+ N!.˲v\(m7vk5'y5v;uWp,{6;x&N<3*/\^${ 4I("84{, M^w.EJݜiq.?PEB/B%@N"9i3<?$=(oNLdD^aRXm* ߉JmߦȎl76POhm et cxyj}A g ǑETbN[45Z-;e4c(XM’ UL>Y))~ k!h׋/R\%Ղ_c]L$0DFeMfKJ?5!;MԀX| sR<:2z}ѽ*&@]GklU CT*SUI\)ؾ֌Nim8F\fPD ʠJSPL,؈Op!Z/6:nvK2HVI/Y$|3hl|85k`-}KM'j',UU!9(]`֚}FְٓcxG3K!Lv5"fH(-wģK*l3P0;ZҏWq1_$<&=+na~@Ȫ3q%c5aZ$ߥИ]/K:|}œ5\$coyפ##@:k%a| kQeJrteQ++Sz 7vdHߔ- /'˸31Gka8p+,G_DH,&Z]@#<5.fFR/ԻNJ+P _.$ۘNAu|3zXkhd5DXg~⫶5zyĥF{eJx1yz2yqo RM5oDDhXou Q>S?o0UXINg:&xVRC)X]gG?6%L,[wKd'"[8\; / ARU2\,9 b^]D } #zϚV򋺪Zr]KP#+z͏겓j~զ}%EJS2 ؁UxMʕ68-M{P9,LD4: 7QpfY ,F-y _,@j7 U}"l֪/P-}K]6 c?’ ٔ|rڴI&aوjZfOfC-$^ =Bwl^ Ncl0{<Qvs=:fvnJ8J缠}fKFs߱Cg}d1ֻiOʟ D18:a0I1]|'Dvm pBiA|̞H,p{T6OR;.B#oApX?* ,IJk9T2?l?``G">!i1$Ɔ<e6G{g NHNOI,hnFNJ ѰvX has2>_C {W'Z)'} նsڪFn`:OϸyuaIę+E{BZQBN4fz!#3̓tz)k ,]»h%]d^KX|;lQ{dN :<0T"չ t(d!Evj̘-i?ǣ=<53N/4q0 QxVNsԃ/yүAQ,=[Jݧ*$cZ}vbetJ;#$6zg)ٔˉw1k|y(|ʱڏy_ c~Tyҥv@v͗,脬m/Du$i$U܇Zfg#sh8d`ɪ:ϳl}A 2+/=Ln|Vx4OFto!!4фGdR׸R H%ֳ0f hO{#ƙ%v`Ԧ骧 ]3@}lז/.02j)d(KlǢqr!?nO*Q@wL$ :(%OqfʔY:ĵŚ{R)]mx*^&-.Jr56rW7̜s'nqGl7%j-l+kD7YЅJiՀ$UpX_w!,圷G+n л?/&RCv*Zn I2$mdLһbu{} }]K^kQnvt$1[p,tl3Ҩ=NjHbz70襢=19Km]h@6I'Z@!k\4 X1S:Bk{py/`oo^TI4lo}devg@Nq_іgqmϽQ# ogozb2{&kzcO} o}$à#1WP\֛fi= ߵѮL'lM^bB/9ޗ: hg1yΏD#B xhU5yp+RVh)H]UT$*0XqFU^Y+nS֣F< jTccMl6q4j38wptYos1`Y1 2D 3|{H}pr33w lnY[}~&V|)mA˴et\8)!38e i,z-k2?~ ^<aR+ɉm MK0e(PAvgd6Ɖ hV0<)X@/Q=h4eZ2@iu_>?Tyv@6⊏& \~31ow5 R3rh2bC#z-Sd`R׍65UU+)P'?G)uGObQ-JWv&I[%C R'Xx&fKԮ`G 1\/&rJ Z8 \vPL.eb`JEsqEQg}e86Պ;BV\צ4B3g8ڊW$Ҭ=47r'SP((jEZa7;u:f`=:Aw2/aʽVߛՃWhq-gfFj48xH<<'-I\=GW@p(Yv*΁ډhTG|chmeP6v_/A%S]З6p5(- F]c" ;{ur>|S #U/P.'*$pQIJ(8D(#WUdKrq*s]mp=gUs 8s65?걎7b*Ζo=XYPDoOj.4{AU!1+'S N"Јww~´b4*8Z1 ERx7KD kg1~j5;WM`s"krحC PH ~]9icR߿sQzeJ^}lnގ^K=pelʕ+I7z4ThYX$q'!rP:H'pbuūK}i(lEǂM/*-{&{ 0\Q`0N߀au-gMVS JCN97ݼRPȢ!!T9MF/ I28Ypq֩B< ,GfŢW=9wN:}mro 5Ǯ5J`V>/l `:BbA 1Q 0>[wJ܂y*[70މr$7C#StsEsAҔnlK@Q绤e: !ਓi^鍸PHA"Dr=M=*ܼ s j-ҁiYa1|c1?1rNpT^otl#`^+VoyA9Z$ZAc4yR Q1RWI+N_ MӁٿQJ>y[!4|][ryGnR1 w,$I?X\#:*#x/(&j ){%7::3)QJ˫O\vk&S,&zxs[&o݌-?PY|{o|8bâY~ ne׌u^ːRP. ˆ+p:q͈26i ]C}TƶUfUePqFm!o҈֢כKւmhƃ)_zrm y$Y+}!Vo49yK‚~SQYK¸/x4Cb;W]1M-'븘M^^^b&7SzEYno{\&1nsseXdB̨pK v=-%6QV!9 L:~TĐ9G4ncoA=YUfcu܅2ZiO( /)aY9k= G۟ȫ`zxu㏂wbǽ)|pv߲hLG@>h"@vtB01}ltNUQF˞Aquo}Q ^cѮݤTY+^4UcnSfJū 90ox\ۇC) pJ.y#bӦAT+ J[] mq{HqʌDŽHIFhapYm( E :ylvT{jR(a! gvp:8]<Ϧ[FjW W}q(q:|^֬}ckS w8ŶY ă!Pmhxj"edAGeE ZQaX-\U>78!jAUAߠ.!6"\M6c | y1q#>c+ԄR (C`Gqh L2b(nXZHci;h!X.D(&A . *< ~zD s%XOHhT?/I$h`T߉HtWA2v- LڨgWeyirYҢHyƭX2";HZAWZ(G0xe3";`Nj>LMDzN6ݨNsuDДwЇEnx)|c;8pAxҺKTx[d\Bp%g!y{aM&&ȸMwi3@}3%h$؟uυ%dYD^ nQ\jQxx^UD]%IS 1 nt1RirWaZX0(8#;:T2HQAkGX3cL 7xƩ m"u V*};z*B/SJ:1UWVEleGa` P' a"F5^/N0~PX 嶼C`ZQ])Dv/Im?P&.;RAW)#dOF1]x|vi@d#&sם*ѸǦeh?ehMV|~Z ACd֊R M^sւ`KIX}h Ktl)U3ҽWr~̣kԄڒAmyEOM+Tu;k1jgҐ*`- kY]"2M3]T'~Va v cw<7xDď$;i@cN cH~5$ yDZ@{ 9eeRzFYh,؏ _ $sl͢Ȭpߝ?Ixt+ݨq*{3@nއ.܊2#mL{4@.k~%',=#9mcޤA Y4k,@<8RyQއ] [58 #~*VK>DsMYu"LQXtΆ (;k/׃HqB9RK֐|SۗgXhy GS%hag[՝j: ? hMS+C_uX`*EmqGH]xy6g0rnw,lV! ݂ p#9A<1<PS@اu7;+mCGJ h |UlQ+..#lC]gԽ$9?x8|pRY]<ȭv)5}1,g\`MӱiIXʡk殚m(Ι I =)~ZQ\1F2f&X/Kw9"Ƞ̓<Ʈu^ؒLfYޱD/GHPXNfVH -FQM/T03j*{J_>"TeȆ16kǜ4zS ae7tt"Ny+DIA9RZjI:UK4Q<}DN*V&Vl_B3ICsl8Ul}hcCZ^\c՗ko{pqcG,ƜHa+Z-uӫ Q$cS ¯Ckw?-&L4"8GԓPFSJkaK,/K'C-@* u6Zf?(g1D͊葲FGdI`17b^mӛeהSRiiG}Cj'g!Wguk 4, V fΖ%c۸Oiks;|&}+W!Wjr,샙ǴfLZC{,J sw@e_7p vڌ!'/ǯ^2f~Szj+/z ~2MD- OT:F)~&\Fg`CdSg#^S!yL_- @;#κܔ/.-++y7 ׬}rU7Jjk'4{FŇ Au QK 1fI傊F2,3$,qRj@1@+f\XZ=}OJ%5f@ JP$ew,}gxs$D:k$Cp[؛31 n6^RW buGDץ7OVm djaiµ"\:ZOES/B}_v_4r}o ݚhS:d5d8cJіo(?&` wLt;1wMrv#쮣1!YvmߴM{7:睟MOr^j.wv; ĦCizg@6"<,q/yR٣F)QKTc RL//P? wq}f /enEi ;m#,VSd@xE&D.EGyPKE˫}>VN'N'Um˨. q W7 MEy3aZPN l!:='PI:/E$ր%{Yd4Ĥk-]C;ucMF0ɴS$jX;(8=ǯoA_5fÁSG ^ |ś·z~+ecvBX3rШԲHL &$daKa*u?rhҐ*qR-Bql;8"3yMW.:ciMaL+/ jĤ\ӁQ5qX$X{4S=2!\, LF 'HP$ ,k|?OP;1jŎ$Yba|$r7Y2/U͘K-;6k$Qw;_DYOMv* 4]L (KԽS,eދ֫S jF(|\,>V%:U>{tempg̞u2洋ES,u6_/ÇӪIzU?LIfoOGE9@5^|=4(v#<I:LFzφ*auH0ԟ5Q衁ByK;gI#F&zo   TdztcuP-qAkr}Ui k4ƶBI%=ȝhr>SWIܱPso} MWM|ݭn5S%dqC !WRH7DrہNb߮,qz ;@HOfǡRNŪ_""~P}]-  k9J ,r̴ 7"hjF~Dd.6v/7X,N۾}tq:7OI@9F-nes/E2$TTH#0%vK%d$Iv8]f9Ҧ32}'L'*k*㑯U[0έ 6'l#gOn e^ )lSF;p8}:EW9u%xo ogmKFX3#3ӎO/JQ:{w]@2#_w1y RO }S8?Y4iksj✩C'hN, GɹkNr<ֿ^;҄!=2ʫiÎP:AFtb\f>~2"гaWev<$i1C~jT rwZÉ4i`l K72]jKJ;fޖJ/|RJ2KSf|k%c(v#pzu% )dNv}~; FlhE?0-~~hV?L+܀wSv#cu}'a[e>m Aztlw~sܰѷ$UJ5 !VpSd!D< ^MdO [fI :e¨ddVu -e] =LwJgN2-ƘWK* X(H޴37}=n[~~GC?$ͦ0y}OVpj"LQ{#u 5R?L7Ejyhtg6kOz>~*≐Mir&s:`s,yiOfof̌p( Bg%g|P򼔐V޲/ڦ{ S5-)Z \>RVj/TLBZ3ۣŮC]܂]4 fJjyUQo+-ؿ6:7E8_.Ü~Ek3m 肘" R5P](jT)>bΚ?rIy#EF-cGԧ&MѻJ~Nj] M ES$#1ϯ+6Oq[H|w-#u B).qzS@n\l[v綣>˰pn؞É%W$h۪KԾ#),:MOLa*g CI+_0[@ ,My4IO=[1陘7HtՊOp \n 'u5AGTg`v]Kg|b4 v;?Zv[a[y.kdϊW)Au;W~ޤ3c陁)ס]m)/-/>aS<֨|xĤTn?LZ-z=t_\3ea3Ӝ2EPo!:pͦȴpWjx!{zQFwQmVԸUe3&}ґ44o 8kJ aq8HB9RY P<-m0KulҾjs)E?:jN`UhFEG .X$DZUSkMG8zdGKi/푀C,6@ dWt[+S hD%'PaW0Zy 1.7S.#c] 憜pv!sp i$)?YWNEFʜn3 [r|ݾ 5Xp.[+*b+s,}^KD!`sml+Qח*wF|:fcex8nG:7 ԿϷ:{MJLx#fR]U bZIFV(U,}@ .߱ٯ)V:ՠ`lQ ܌4$u&e h _u%Y=YOaKIbJb u [tR*p$`yE*MJ/5=By,j 0 bHZ7$K~)酀lfXS.5=nyP&dž/=p?yooH#1hgsQvs<$771N{}^Et$b#<ۂ5tlh-tb|h٧^ϓ\WoYx$Np$;)IhŽ#~ٳ\ԗG'[?`ꤸ /XEEQ8W]+]0PLg~#E ixp;S3Jat)vr*CAMV*"W92B#s%6@!XEj0o0\s&_ndn&} O"5Θ3GⰉwDԑߞ >G0rړ Eڞ:pxvlӐpfleq=tNҷf0.>g0fԹ=!a)GASB[ A+SWѤvgZ"ʎ!*87c~U蛻@5 TIċI`LA)vb }I{x[ld8_Nj^i@Ks{d-/YB)R"Z:FL;'kgvfU;DŽ4ϛoㅷĚtSX.~Kk|o]d~Gr T/~r}Ka'B-<9_PZ\`ͳPŦ[)G'lZPb mJ|?!|0^I4(4̮2aI#X>0# 64 z''~ Κ+7?8p[SWZG.噴8ӄ0lfިOFf^H mĀ$;)wGECi0̷7#hmxZg Hq" U)OMZkȆPh=v+MpŢoy3[86{0-=,rtf,xf dȂWeES&8v&)\jtÜ[<4Zq8J+mn m0 .\hY<U%IJqc3b$ l1 N@jl}vlPkou=rV _UAÎKf^7iw[nKsS &*p͞5{آL{mjuy1ޕCfC7 ː2]Lקּq7'_R(N¾o\w "Kx̛:A:[1ޭв_vm_|)ATfR \]^*ֵ#}2r},BUӶo a=d̆@T;j_^ Wrg @4<eWgQ aY+ى@fY /%-\8ܘ91Wk_`~3uu/% BI @InqҶo${PMQNGcۯsZuk%(#ʭ; JύE=RZ)>+ӧD^|n^HFn^IIv8GhlIoRsao3"jAMTajeBd ( Gʬ"{ !`^@ЍxQ "aturkGG\jWX&Z[Ry'p c^1N^R+bNO^%111' GO7K珔o&6Ʃ )WfT/lMNTBoxpNxLlq -/ /jHIi_ۙRݏ ,eN. zoX,;IssÄǖ h8MTw#/@Kw qڴ}pJp8k|)5 #`̒|`o묠 C~ս}aկ^`=Y"֤(=vEu>E@+- C֑$PƾyA 4=`q,hu:Z ,VJ|S ӇXp0Ei(ZԬ5#7Tv|Vв~j x)'3*7|~qPfscGvEڱ8>uN_Bvh$Rhk} 7x}.F}4*Kl:l/V M)uG Pb`v'п=O_Sp|F"Q /'fH̭-L/Y%ArI=C/iv?泾 +^E{!긋}\gV. Q˵ B+`gY)OR/׵ߕ}`,i gS 9tSs_zGoD-K+g^g'KcH$cE&CwL Ec\EIY6g*V ӂI\V.Dn孾SX FFͻM*B& %3R)(Awd$i*=ݙf+>MAAQ \j),դ¸:beijlUe4թՍbZOo8F[{#E(9F?K15]hGn, iR8) 1 !v]gwƖỔi(VA"jK{o7haYETŭbuњӌ۷֝I~ơ,\4"d1^ dcf ު0ub,(_bZϮ:H VKG}6֑x̀,{4PϯB?&]Bc 6E 2ӧOA6Yh/(kSK.xgݮ SæfVBK9{OnPRb^;"G jG50-Dd7|1oŊ3Tr@%9S42˯1gb4t (%j@iC)07J=QT0:hIɠ7s ́.E{ũtgСȸL&%!jG߮IfB:yu-ADύ7S3 ,_q@&y1)y[OFcޙ&"rF=>Y#S`\qdE~iOLTZkZ:K0`PH({! YD6LU678'sg\TgHzd+jW vz (C{,$UC5)*;n%ƵŽ'X~qeذ\0(Rտ@[ꀟcژ1گ=c#Z!@qᆲT.*&ffd.Y=Eʄak9},mo%I5D# فU2xG\#7R0~eT,DK&t'"& Mt:=R; qnQ#hhgG{xr$BOIPWɺH Qb f'ޘe;hJ_c@AX)J8݈u3'.; ڨwgjA(< Ld!, &weLfgz!v)[ŦRxb{cH _Kd{A ,iԘ#r9U U!S+Pz䰍-.&ѝ4qSsiqds;~((ӋTƥ ~2?fKO xOMhH- ؃J7t?`x`^/Gd0ff-?qGY!tRIE/I\A z+IZoHQT5I/FLmh`xs3>)L $namF%WCU}2,=!*edB 2t /ٝK"#txPɲIvߣP s?V.]+GH뽍_f_c/J*0>\ɭ |jPn1@B5%;k2Am QzSg?lbЪƁW7-R1}6IFnӽ:frd0XE[%/ l'M@ n GiSZ$x\. |Ҁo989@\W[Թ"krlPcB]% װ8,քJoKI G:{_?d[9ޛig4EoCMښ0(dVL0)1a//8d d HF+ߤ`u=:9)E9uGF~@"-ŮE%vEeg?xҠWp?^aj6tG𻹲16qdc<R\22*VB4o48kfxw'@HJrJ@`G|$V*cskoB;\:j/9S= @Jt}lLpQfC!hDoIgu /k7Y659NgZN- /dk_!4wzH ;<+SJ(~| .}z:(1[t}h_~zZO9wV5UsYlc{$xSL0w'T=^4WI/i߂"vaTmw) kbt-G !!l–"P|=KId&ը1=sqοv{D9ߞ_nDeb 9Pp<rL>wjЄDo U3_,ző.ϓߚMK :t ?}fk;Uql/2.Ip S,k?A6agA~Vf&,!>~XzA1) %yz,!ً-8CkP JF)fT_-O!.~{!,j\1s8+)nru@F8D}wYd:5⍻E*}Ss"RKzc|3g=jC-X2/cPߕɧn.aLH"[+/QYX1Rp~6+[ A(f*Sа?$әۂQ%;<][O 4[˕ B>0k~6~-zt?dnf|G571(e.;- Fk/ eJ|T87\Gz cW^4zڇiB\w]j1:278{Tui+KαRpe+]&o8;f Uc|İxMjdXx7/18Н>[FNR$[K@i h,_L[#";_чpn,̯w-D% C4mo&e_4 /%5'Q2=*&bW2Ýws%Jt($"mYa`r9`XX֬;=r6 .KZ9`@YT+ '< $nh3eSbٳ4Dä4x0|{ aJb?82uX ws*z( SZZ(~k7R:]MdlIb򖷬0;L@hQoP~ l&S}m&u.c8bI( ڛ@wK^Q̳dvVJ> NȘ> irU>}(&|5&/~m-jcsYN}|"\y͹6#jMu4N∎jSImd shg8,h)C3pKdd,CC\iJs;:ɑjd (s4JGeĜp'&B6>=IZvYksZ,vK 96ɛRBwroNbEOnJ#hh=lДhH>uCqή&:h1 ,3)zދxxa ; >fvdU?xg *[A_ 3s (n's57th0cCg0яg_~_j%@Hr݀Gf1|66K8Aw&HM楧RЂU%AkUhWnEx4q-aZv{[{T <=gӝT:"efJDeoӖ خD*+5?: N|BL$",UTQT۶5Ӗe2W*of.x 0fl,eY"F_*i0eFV`[3+z /xWE^P.#C\N0b0eᇅ 5 PS|0b5,;>n6D0oۣĆ6Qwgu`[+Fʼn\\g<ٌ :㡻Db?NoOwQ鴇r vNzGv7D4%o>UlxUީgД=Iբ@a]3 Y}0dA#5O0\29l$& CXz@#n,HOن )ٷ8Į.CbB8QGYkx6z< m/^Jz1\}Â@2,PV[ 7Üy)|ev09)8{Tp Ph&t}PBQ3H)Dq1kǐ:4xuٿgre[DaASb KD@eq[R|w q' 8:_5p`rb/z` N|xO8y`~.yh,T!~ P+mÒKW`\x@J>p r[ubL9exH ,wù%e-RzF%cӥ daWd_}R"+*eה}1#t#Nn0RÐK G܅hoi[{,bZRMBjI\y}Ltpd:>;\α+*A<;|*= v%'P.'ZMNɘl3)"ͻB-߭u;5#:fޢ6΀.PVP,\>p G;܂S&ii觝bJu[)ECX~%GxHf[-tk>bk9aqΚBt~=(4qoXxB[mS)y?^"vN5{,M.}˸l4hD[F$FoK0S"zP V>v4.OGAU5i@Pg\\"&ٷkYeV/AO0|p΢DJ%Q? q當pC`9|.xqOXkd#v4݃ CjNxS뗚Cĵ_Iኛ|:~~T*Nr&A-Yx ;xw%Ac"8!^J# ]"'gQܞꝻh'4 !_T9{z^sGTN`ά_C9Bp.wVAG|lOzACke&3S趋*;(a'wr(k |O)DBɈV"7mڸ .$d&vq bL?B7wȌ(7˳G`F8 =6g.@#8KN]BN'xgZ#[pqa`%9{ՠ4}%ߗJ#B"NS1Q:"AJRfYUDG]4]G.BT]Ӽ̸ CLUKPx3H-2WT޹jGB!lԥt SoJfg\ΩXS R*',. Z XŐ2*`Jǥ6 #_GH]dF&Y HS`ڍD4_LONĄ'=FS3 $bP HNDc%C apFM;2аO\VwICX _rf,b!2M7O $)6BQEO$D]t4Ƴ Pʍ#C?4":[+k L+a+ ?鄑A%Y:P~ +'Ul1>XZZh_5hlo]4]Tܞ`ƫ)a>u0hUC[$<υI~ KuB,aq kmQ}ɫ|q&޿ԂmeB "D.v\ʵ aʩCJ{@<xH^}3 ;ُ%hi}0#IT:D41/eVf_$yn'6qr~&mL#%h)9hN* HЩ"Fvo oM鑬F]yiAaβm^2n;|xM@nR NZ4_M?05z,˩{YrQ$*8.' . ӓ@(ݨ+0z=Jߊ_i<М?K}3{EwgZ63Ms9[ҿV a`ȿ9 % t[ $m7ﻬ{x0wEo.$Xs:(yNy^cUVgTL~_zL綅HăYG I=Gǀh(g%TptզskG_Tܨ0-}3\ 4Bxr |#HRLOJSi:> SsjE$o!7&~>)mQyO`Äo%WSMɍkzE >U9%@3O!β9y |!Ų0g;#ѝ&A _.5FflYH_s7*a=}Fb4G3e3h `?X3 wfM+Y& EY*dԿcOI4BectPu^Wr-?lIVio;>: -hዧ]hM MMښ¿^vkp rT^ܱfϨT&&kIkU\5tu9ӟ|K[8!Y ]Te"YN9i Z]Ze h|hjW9+%xj10=9'jSqBk d@-+˟$RNm|6ʆuUt¸EG)!Gjy$QEм[y tܙUj&y &J[ g>*iTGqN[[p+!gH h=y_a^O]~c>M;V'č[j{b=;QFAC l#xD~0_#fa=F#W/G-[׻ J%u|BzV mhCɌHyZ$2(˫ NW3\c)_1.Ҋ$#"b~ɩϺivm^ly==x˰pzŮ(o_U?g MhD]9U|A@*nP>񯚐]h5__.`IdUCb\)&6b;nYko_U(f]i {;ED}0!_B^o#@U|L,"0SR+(N!IcT` ]D;{.fK S$5?iY(t̳cWq6Gr͉8=p'%mEBEȧswx M,0p^:r&!f}7X!Aй|>!aq=4E!CLtJ2IV ѥ^E. 1^݌bX:O8HZgR8~ͻW! _r Er(AWQ`P"̛3=nrgA!ߌNscBDJiDU֮!L(p/Țec؛wX:"3 ݄0i1`l?ToI<cWLn!8apfibz߬Y}K4y?!` iwTmxo,>=zk~!EcIcE)Ү[036K/66z@Yl.'Q&E ژo)Dp[kH;w{A;M=f8F9Db0B#:${?`Fur0@x]ޥSSyFqUE%t aR$zT#dz˟#UE0,`u2.o&K?dk$`^EXYY Sm0^ -@ q$ ##f*xXːI/Z9Ҧ0z{Eܪ³pm31]c}Ѵ8]Awռ-H\%mp X%w&[#V0 +}ßHj+_{"ՈXFqev+D/cG]Eڦzݞ-y_=mK٣RZ$c5RReO_x#Ǭ|Xu9,ů= 3}𰂟\IHGĶ-ǭ:1[ s 6wָ"=BhwGS/taBC < ] 3zYs^b V}>vq0r2gޚopf7'bQÕ-`W?PaӈYbz6!bٞ^Y5mW&F"@QZvyE.S&A Nz. dvNm*b%"5wqQaH@ PVްB%mȓ#KN_|iK]wts&,կqnr\:\=gN}S=+!akڹJF|w(Rh8rE7x`T J' ߅.?}^W R >Ҙu eQ]|WtKsS8>,$Mz2-Vne̔e $LXɡ ;Sc֭ΜBB(}-\/rat#/,bY4el-3M׊ԲSpDADI͒k^ b󧢢^?yϾ@v{&=6a_ӼxӹLF2%'ލ f<-xP[/pGpʣ@)`2mڊεmzO%[t~P!MPg׹DqoNiڋymôDd (XYPercf1XڷET#IM{O' ;L[{"/R}:ZZjVCDs%o4V 6 0rj2ni9xT\Iq▥xl(y.+šthlat^(U@t٭ 5,2pq>걜譓4GMӤzXOknh~}/\dy>@[N`@5GZ* [5q _ؐscFϻmw UiGv$4֨QݺcޭP}h/u;4n~K#O9΅leb/wɗj q΢dgqu\DڮxTrق0G^C(wL jxUÀ^cd ~~ᐌy*J[;MZ߀ύŠ=2 J#pǻؕ^ld_R'@rVjF$Yk;ʓ=e'$E;ZԚ $b )On˓#jbɭbwۖfoO]'wäZ' }pV'f;55]-l]B̂{죵 :@( "@ۢl9iw+}+/GwnQcMOlIV![B,f"lY4+N>6$ƾupP:{EZVӈ7GW/R VUg0<0y_y(#&fM۹\h{S=XMFq3(ޔQIfhv^~#7Z&QK`KNb*))wE rb+402Z KheFB><,9)#^^u7ά9Fi5ܺG!嫋/PCLu 6&(64rgD) PZ *|:ZV]e-Qu`0R)s_[ZH)bA~W!20p-' 4gvjW|UCO9OL%Fa|8"y_#kKd7?ltߺ™D$<[0`Oi*t*L'&;9A]f&ŭ mLkBlZp$ `g- 6V}ۛb- \^G;~ipeJTfzUd11—R%sg̝S5ʜ`mb(iBOY5f>yrgby)͑:E^0A3$ G?T,sJaS1j/5P) 6ۿv_@؃1$.RkAB=d%t'/+"-jbT9olf'6@pT6Ґ1nK퇕%6\& mt3vewCH».<]53O/gPr A3Ƞ}ȘO Iy8 yו Ԗ7Jg^Ƅ,?YowebԜ>6Ź'Iry5\#)R; 4ᦾO3v137s!&`9; /^qBȽV s?n"OPg䜜v7o#OMj!ILoPg6it3' r&c6A̒%%.fΎ jI3"7*t_f"+ 4}?o1)^_UI8rAJIm.K:>R mÊk KFt(zfŽ|QP+!miJ2_Ps!Ϛ )iLP;&b*0bϮ:O P/LeC\ C閱I+5o`[s)k%\mF/&# zVk(a߈VCLA(?w9wFMTRxݺO߷9q ȼ7uTW4@o~FKS<,fs#AE3?u_,c1ghS+XZfX%Kg՝Ba3,~^`g=t:R,X˽# 3ln᎘ps}&z^{~1SE@Wd;ށyb؍þ8vVKH,wKjȌZJ[ZC/ldQ9hev4 zؑǮ9>XVaH5O\#z+S3C :s8elnkP+x6#%tbZ3Gqkj^}g8YOt,0sdamVl0Q6ܕgbW"_Cnȍ?qoy2PU*kdOE+^\un-NF^?:Ǵz7 -N`O\ݹ! v=KXgcQg85%()ʍeC,iyRWDPbxYygQK22NJP|D;i&+44RPX t%fY° w3SLfDE0kyb}>O[Џ s, 'T3*eU4wQPFI~-i%nkTɄJ`tM{w&F_WdXq@ݹ2e#vd8h |1LݦwT%]/*D{j";ueVI8gvv O$d HuO5+L @+޻,p ىl7EoW| 3J9;nC eӔ1RD pD _IՋlIJkpRNqobѓgL@Pd *߰, ήutuU,9N!P!t;J&%d7p?ͯ9MtQmwЫ˗ DD@uJe@K_qr LPG3Sj1 _1U``)rw z6ODAWV2PCzo|^fS7Q︊黡 7= Arie  r2n?7Y+/j{/:~A*)!-Q'#` L6󋅶eM&zoSW9 $|>ljPmy_vp{b@nw+NHV>: p%ϖ,(4Ƅ֙ŝq`jRrJc߄ҭ.ٰ"@HzG#,ﳯQcakyn'i!":8R@"3V>h^cWa ˊJܱ1Ic1&%<3;m14{пǜʯ%JPk]83}Mk=-x_=qZT_ʫ1HSj-?cT}5%m>'91d$uBd6`F7Du9^w~in7{ŇR5:hݲȽ(J+OuC]# ieP{2~T!G V|LHG eKh,iM5#Fh=:;.$FK-m'蒮H>4qt}cW *}@Xeid-cȷrq~-a1]=;FrUISP4Ez.fp a(&ڗݮ\ވk}[ rMP5\h2Rj9,a ] ~\+.G"Dc^+9=B:BO;$DR/4IkWxba`n8>s@#zŭ 5UE+bift5_#c?0M\4/C>z]~MfEj,0$O<| io ٰ("W~ol0Z-S;qj+~;t4k5t>*x13<0ݗ: ò)0=v_Qx#åꋘOPQf8wŵ,@-p#%ts=_JRxp«u<L~Tip;Mw \#]SB11\[`&;Qxb14 S68ɴ)u\mJng>0?2N.(uxd4Jw|0g|ÅO',(ӕDYǼqO zrVbh*'R~=bMAcݜfA{d")\!zZ"[Z)$N)2H$'d<77B/p VADw-L{):6ϧ@2ʄߝ5 Pu4$3qr֏fVoЄwpB<9ii8_[5Lq X.‘Ö̳Fq⥠XY`E3p>#266%H^]`$ڽHPwmLFlW#(FX,\F/2͚HC~Y+陉ҏmmzbʆ UO>"% s4SUX^h^hLK 0JD_CfkGQbT,M篛ηOë( :`P 4;!FXQRc iԌ.MF:sV'0xd_%UN^r$S {TO)ބ:H%RtY춅3#ˑV|ßFiK~ѿ!в8?1bD\ZJ!gM{Mk؋36)fY8a|Fw(фW i8U["gfn?FWrM]k$W l9 ˭=B$񫈸.<3Mu</Ŵ6rwAN5?7/"lb_!aьѦ|qG8gM2 SBT+츔E޵b,k ي_:X'2/tfnIiOE c)a/,2+!Chym\@$oEg?p hU]H_\a)x[=3Z$3uےz$SAJ?n@[(wc8f sQnnp9 =I]X-![k[gʔK ;]M¨_A1~j (rW|Hte䃳:|Vd~1|Ͳl؆KW:7" MȲ*c9GG6E[Ij !R6, JfDQiҕ1 Zu[|^Rdٶ(0 {!ply bFߪۋ1£RIvIڂvKLQ~ (/H?i.iU C;$717O d Z:Wβ(;&\jXhm٧. y咒z_5czym\PYMctVPZ)MRF5gЦ1n,Æ#g["f}<5O86>d9DAJOĺΩ$gpq&0*#bBp y1n}_(=$V4Ƶedq.Gs@.Vx< Vj 4~Xs9/Vŝ,BI ]Rcv=R4g cSn2DzGAP >!.g:hP#M F}U5sWZH klȁϘF ^q-j``77A䱿T(g*ti?-5+}D픕͢ [h+R"xhR4$b_ͫ>^Ti}kuXv(}r3m1dmէ8V!!'v*rFQuִ6 `J)hsRc)ҙ vlWJmOW7D^\YO ?^HF˘c$aݺZ%H&ctxe:^u/д12&XJ3Pe䭢Eܭi ܗ@ |֤|![}E*/֤Z&o:_G dxF `)^K!yH@KQ_=MoZgbEyyJ=~Q6bⰔC'i'7.C޻u}) fٴcX{eJF؜³ yJ)$t=p􉸅i彂X+ r43e"•E[|OdQ2E;lHlF.#A1%e|48 \f<=m.U wq'`3e;heY,,K"sF܀\3qc < [1N$W'F% &ST}zXN7?ַ0`XG,nZ:mXa!9!n*\I=\:|FL4~`Qz4!69AVjv(-f?6f m'/_k FBo,{,rؔ &"Oj&3+2r)x '{J_kpV𱄐Ww`HgigUxb@/k*pK*SWkVh["GaMt]0AE*a÷DE5 ؼYK+ B f`AAm4좬C6S+lt݊ǁ1[^hvY9uwl0'Tf݊̕Gg!P湂(MK[#'ϫGo[aL]MN lv'Q}>L: 2'ܽ/h3'7V%#(ȝj7E6qcj7yn*!~ɇE:Bvu-e2!Uj;BD_qHI 07-R1V*r]qVfH%₇\_kF+x)T.Ѯאš^>PMPZ{w̔\11RXx\ҟ)kvqI4EFQ 나nqs괔o۱['2]ߵ-8e`o% ɟ,rC4Gcl;iyݛLVKyq$"EJVq#Ծk U3"{3ԊLik#Az)tOKdar""&&| @'٩դAQ1S#NwueR(H[#1&s$NX< ' z\l|Gb5 GL"PTGq+ i3̗HDJSR2_q%mlXlu㦁|z5AΘG Y~]CRu[&wНj5ʖ:egh%q`s\' l JAB Gl]hҿ3O4%=ޢLIʘB48EȘW~j!PEw.;Z2?7n)P?sRs| kFݵ/Y$ǺyՋD[ LItN#%і_X2nPK'̣}`HokcOV3ZpHMvElJA'2dV!x*fȖE#.W&&#LGʯrG#pp0[KH)^gB$R[|i4>5 1dd?+ۆ̈i3ҭv{v|4Un__x8A;W=Mr ,9ʘH EwVߕÜ)+1ܕ"{ 'RJŔ<2GBh3DxЋp" %s'!BJ_ARcie657FhcV+ {3[h^m[bNN>bĘ3̼B4Ch9Ab٪[³ϨtTGN2Js_"ڲ e}z8pn0l0Lu5|5r l:ȒV"3%-RU)iCQ>zh3K@c)X;œY)FY{Ђ9K:u{O%`ndˣF ~#eN 6ks'xNʄ>yLq!,D;"S%zJb#97)h-2Bn[3U! +[yS'gE\6V k7A<'TjMpew+Z*ULtIzU4!w;Աvn^l pBOԕ[n$K6Bd7cq,{ awV#VbRܜ!TKR%4;=xC<~mo.Y#*ds$xEa#AXt@͟$,]¸)Լ+zZDx](Vp>QA`nSPu[-o~SU<7~on)I9%$:_`I:ˇtrׁ{`# %AW/IFb S!حxX<B  |rT"-#I(7״mbOҭӳE̞]LT_  10$/x+8 \૞KGM褐Z睞p>?'- f}>?$#g5[] Ν݈ă/_US\n<'T:;=?lkBچӃ21" 2w$c΢(R\pE+3[mJǿQWAP~ֺrv%i8Rt5hEt1?kDlA6.kg\=aEyR4L* %WڟciDóbV+8A T-PDq;"MI|HU{x=дl6n M- G5 '^hIBuB`J| uɢv1م t )ӹAV_0܁5-EJ$(zhIc;Kh-Y%WpzGdCx=3xZA2W$_\#KSƷn|־+ x.)/6T5 1L~g^*~+m{w EaxPucYMv<З ndι9^f$oR =iOKU_I%: s|5A)㭜#+\Z-_I90Bkl:Q,/RI"XgTR(X> .r/Jv*X\X`}tj vXY;z4[.rprܠs*BǍnlGRodɣہdn9;gv/`n(c =< ٽΐOfnǂG jTی)o c)q#Q5 &dW$M:3)e6_@]ˈZv3۷te* )&nkIBtt LudR+j2Fs#h.oWPGrRam:B)HpmGYu3ts蚂Q|fTaFgF@082w(mAG*L="݄(b84HK(+$1g| .z) W$)7S{_[t GzI(.b8䴏ԍ|aaJr%D-z`G(|>O)X^lc3yB>'5Hۗ#RkDZ=%*ul k#!PN (i6_Izco#=D5!8DT$ްpl,}HRɐHd2ɣҀ@OjN.ȶ=U+U1{كP{D K+Wx*ȱ(gdozL?L+;Ɖr od