sssd-tools-1.13.3-60.el6$>)L" S^_ń.>2?d   A *HNTbb b db b b b!xb#bb%L%hb&'9'9+9(,Z8,`93x:,GbHbIbXY\b]Db^4bdäeéfìlîCsssd-tools1.13.360.el6Userspace tools for use with the SSSDProvides userspace tools for manipulating users, groups, and nested groups in SSSD when using id_provider = local in /etc/sssd/sssd.conf. Also provides several other administrative tools: * sss_debuglevel to change the debug level on the fly * sss_seed which pre-creates a user entry for use in kickstarts * sss_obfuscate for generating an obfuscated LDAP password[)'Ox86-01.bsys.centos.org CentOSGPLv3+CentOS BuildSystem Applications/Systemhttp://fedorahosted.org/sssd/linuxi686+ɤKSA |5r#1FR :bo3^ 10m:+}MHOt ?tH dC A큤[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)'Vpn[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&6e0820314ea3ec7bc18b1a02ec3301dcb834a52ca671d60e8bbd6e8dda29149e10acab9502ce2e73014692130c887714ab86d0c8455e3ca3c60654dd1eb87dfbcbe626e51dc7fdf478397557ae7adf0452f253bc11ddad6cb89d4d5fa8fa20087f9c819356c2781dd47f9abe0138a5b58c00d63fba576d13b27ca1040181516e865c4f8b05fae82b77e7c3d36a6b73bd717a761d707845344c65ad8b31ac2846074ea22f08e186a8f16066958ff1cb7da80f4a744e9737ad3b619beac9b0a45e4b5ce8776a762c744f1a6baae5545d31d9d4bdcfd2db99a12ee83cd804192a1a38a9daf34044a114e85b3ee4965a4712cadb8857e38b24ca88328bcdd9c8941958dbe4f10a9270f7343dd9d7f90bb6ad02b51363ea969a23b8c4282e241ea075d09230a51dde5dac102de3ec991294200bd38d2e9a330a9bf9d551d987b0697948f560a1d2c5b425b6bc3cdfb439f6ba3335a7210d772475b29fff80ad4dc2848ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b90312faa0bc15ca0607109277f9e39c1d5b3f8f870b22ab03d9cd843dcb4937f23c898d9b4aefa781bcf8722e504fc5ac11f5d42eae2fb68dfe61122b8f98044a5d3d205d14a01e31bac7159e1ba9e65e1cd92e17b72af1eefd70fd8129c07bfa32a37e4f153c7948135315a93ebc523b5da3ff74134e37db1e58707f69f285995751ea01896d4b36ebfcaf460822c8e1fac3591ffb8062729702047d1feb185eb0306a72ed47048c15ba94b54fbe85fa0488662543060326e892178173483a35c79a25c04eac19642dd5c1de9c5715dca1978179971b917e21570b05010d9a51b6cbd6c2adb56fc77c0cb0e14d4575c99b507f6258409528ee860d6608f5a5f4e68fb90fe31e5abfbf19ea48c634aeb350f5c77d359556d5bddc40dd343e3210c50d992b8829d02b047b0aed7fbdeb05437563cb120618042e1607c36876699b64bb8e9a900564768929f88d57e798bdfdaa250ca225e051773c9cb698bbf9cbbdfce91ac10376053bb29a9e7be4ca3d0b44a5ee1c40066c9053b648581938913e6368ecccfc089afd5d2db3d4a993d685c9e24df43ba9b89905ef3da0ee317577d7359fe269dd50ceffa06e6d8b31d815fd3ffe14624f40d30bdedfbd186e803c731156edbde991952c524cb249c9291fc6f1f32a72b048bb8427ec889c6c3be2ae986e869623bbd719ab0b78d7f55a1c56ecf6349e6d4bd126636f890b355e35139fff8021748cc1c1f839ba681f08b2574bb6c7a5c95ed81a2eaa4f92cb927c5eefd7f14a2fe6dffc5e3daad37726aa63767189e2c6b14db2b80a8786fa81166f7519010c5f1a629c2b526106f60aa71352c22deac55026791058021208a55563394c60ede4701240cb3f1ad645d2f050d3fd896243dbbe21d0f918c1ca668ae1442c3ddb536dc94607fbff11a1653b979831a1ae879514a37a3b2967dc68bfa063fbf3e17dcf7a075908f24983b99d9a29ace2c27dc536673bce4f5c295ce806e2e3eca024c9d1c81c9ae926e676c74d2cf28f27cf696877a1ae201716e810a34443659f203bcc26033c99f1f44f636facad0a96186f185c4d00472e1feabdccccb36026a8c926867926b2f2c7a905415c3762260d12af95929b9446f51a1173bb88ad62e35bdb2a27feaccfcd7d8a24550b32aea3537e54e46866edf7a7b325b4546d68e849c368c0acf4416aa1683d9316a636f7a296424912a8943bda31b812282fd97808def916ad5340ab1201943355c75a31b4f60adf5bdee206dbb704998e25bb3b089fba27be6304650028b61ba8fa12f9bab1b7bbb5a94afa96ba8c6775d4712280211e0787dae108363ef3ba1d60b97e78a532362f0ca7f151995fcb93b3d7179c666a6f1ba4374e98880f3999b0d4c18be0b8c5690755ed6db5ffa1f41dc2848390ce1c1adc16d936d3bec7678d75df512aaa8c65ab05a2360edcc4f8eca8c6c7856f81172fafeb7b3fac9f6d2e4fcd7d2cbb3ee71259899900c70a0feeefe148e9380948617378f68caf855a74c6210ef6975dc2076f80092a54cd54279190b70df0e6ebafcd73e1d78c155d693289d3cade81c583a8b861197472ab6727f10207ec4bba8e70931c3c7fe84ba84ebcd657e3aa3058a8e4d1c9d3e47121dfed2cec72d72ecf81cebdc0e3c304edbfe18e7e03a8c92485d1b4dad2edbd20d665af641b9bb99993a41b4706733028b299fbcbe78c8befb5ef5395daf0302535a4b8b38a528c2f5e1447f05fea574c180504982cda4f30526999f9b097ae202cc188ff261fa7f8bc26dd13fc4e5699c549d4b181ded57e3c0720a9a6296ec70ce1fca467a8b2366d359e5f58532643db85c3896c5c2c2d3b2c68a41a713c4a4d055f6b739e2f6e77cf70dcb4307e82ae2b8ad9334c1fcfacf837e1de8cab1147201585bc8ecf5be5e1455af4c28bb081336f004cba4aec2e96ba5e93a0d6e9c554d9e7ceb6b78d89972e86b2f77e4a47c248930958cf35de382e8dbf61346453cd71b6673abbe15a9b68e0e1a9ca23df9475f8a49917be1474c238557624a79130062f62e9dfdb579f972293dec8ae2a4f083d349d624bb2ed68c952191737112f04ed07bc723c327a1cb950c81ebd12eaa17a35822e9cfa00211406f322dc890b40a04379300f907e65a8a541e706503102f4d8a5af3254f5a6f1c3c7cec4d9cbad94da713b12a9a70fa5fd5546dc97fca80c9f3115be2c4add4cbf8f405db62bec3d0a323d50892b5ba8ffe43407551dbd8be7a64fb1e89a335debddc88ddd59e8e10bb135e896310e43b55570617f0a750f8849740a7ce5831149544e5e45a8f85569ea29b3e521f27a3cb1418e8876d29be98db14b44c0e74c4384d2648368c6865b7de8bf97e183dbee9b1728ff2d7e085276f99c941493af78689d832a08118ac282947260339f85171549f5e1100155814458cb6ccb5e4494864990e6c2563b101fae7d70d85bb6dbdf2ca19d730d5587ce1a2b573ef44cc773338518ba1c10a4931d658c8703064c62c50d49c1dfe8e9053e1b7fa95856453a88e1e1cc56ce71772e1f8305d88fd591b2e437681a88c3f49d3ba9f0eea405562aa031a6fc9811410efde0bfb9150ab93167eb0c9742125a7b83f66615b57dc7c57da2d15b1bc49d4a2cab4a8f47af7ededd50cf8a6cf6c809a8fae4098a5d6d24a551458fafb42b3163c130edf0bc9424482ee50fad0ef35016888ee1ca7048d44f71c7f73ee5a535970fa8ad4fe6168897d9cdee7c7fc629f6c7ebf6f91d868aa237fc7eaded2b930313137764a5219ecbf43cb34c44edc46f9326f87fb8486c9fa7474184b14cfbe9a56fd3d94e453c3ba02c7da36cbc5304673d0b710fb0bf7685c2302ef9dda9600b606d122e91feb6e2186fe7b23dfad9d4119bc602b63b8fb841e07302111c6cf39ba94446af50f58e9389102129288b081d8e1273b13c622d958c18edc37fa36dda60f9af3cc4263c599c7b035a514407053884423412536b3126aa677c3994edf5f55e3fb0c4f1827d3ce5fe136083251bd6f207128f4919b7eb764584baacf0346e75f3467f9a1e0664b128b2ea2528ee22a48c7d1b360bc1493fead5f8a43f6a1d9c40bbf656c34abe221fd89740c6da946685148f966c8c378148f13ea8b2353d7c7737a509eeac64aa79423d69dd5e48e3d1ce70b89c012ad0c5ff21e2cc508d6cce293f343a1a9414d42a5e7ba039f982dc70c8c003f6a0aacf3215914efb1f85dc4ad65895b2a883be102f5bffd4b5447d9ece7b535c19112dd777d4d068848d84c51b13fd220519b87d8379fb8ad63d81f1f3a691e1879844a81229da8aa389b6e7236ddce33b6fea7acb7750642ebedf61beaff107e4d53e93592e5d84b85fad07f27bfe720b52deba680abc81b1729a6b6cda7f08b92cf7a7d61acb16d925390d1ce0a2ee2cb19d3f18245647d8e43c69c4b6309ac78ef674fbba769120dabce7cb535c2b0cf880ca163296d752dad7e464d6ad704c850b3804c8ec5b4355c88d8fee9c8b049b55558229481c0f7ec0ff83f557336738850452169ea02047a437e71c085aa5205550c9c5b54d77d51ee2f4e2ecd18c39550b260db95664b1b3eaad40ab0c33dd1545e3eb66c787d6fc4fc8a07428c12300db06f892645e41a5a2c1268c46db363ac492f3eaa69246ae4f4e15e6915f5e7648ce96721b7cf53f7a3f9357e26e15c0c58888370719041f9c5c098919ce2a37957d10a735a02e828cb555ee4b1371fb1e8f2459dfd94495534a2aa3529f515d066ff6b0051d70515e53b3cb52395128c684923c1a86de81bce6f77ade86fef840354705b578b2d4ce19e6df1becdaa80b818c5bd7236frootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-1.13.3-60.el6.src.rpmsssd-toolssssd-tools(x86-32)   @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ sssd-commonpython-ssspython-sssdconfigrpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(CompressedFileNames)libbasicobjects.so.0libcollection.so.4libc.so.6libc.so.6(GLIBC_2.0)libc.so.6(GLIBC_2.1)libc.so.6(GLIBC_2.2)libc.so.6(GLIBC_2.3)libc.so.6(GLIBC_2.3.4)libc.so.6(GLIBC_2.4)libc.so.6(GLIBC_2.6)libdbus-1.so.3libdhash.so.1libdhash.so.1(DHASH_0.4.3)libdl.so.2libglib-2.0.so.0libini_config.so.5liblber-2.4.so.2libldap-2.4.so.2libldb.so.1libldb.so.1(LDB_0.9.10)libnspr4.solibnss3.solibnssutil3.solibpcre.so.0libplc4.solibplds4.solibpopt.so.0libpopt.so.0(LIBPOPT_0)libpthread.so.0libpthread.so.0(GLIBC_2.0)libpthread.so.0(GLIBC_2.12)libpthread.so.0(GLIBC_2.2)libref_array.so.1librt.so.1libselinux.so.1libsemanage.so.1libsmime3.solibssl3.solibsss_cert.solibsss_child.solibsss_crypt.solibsss_debug.solibsss_semanage.solibsss_util.solibtalloc.so.2libtalloc.so.2(TALLOC_2.0.2)libtdb.so.1libtevent.so.0rtld(GNU_HASH)/usr/bin/pythonrpmlib(PayloadIsXz)1.13.3-60.el61.13.3-60.el61.13.3-60.el64.6.0-14.0-13.0.4-15.2-14.8.0ZH@ZH@Z2gYyX6@X6@XS@XOXJXGXF@X@X6@X6@X-X!@X!@X&X X X WWWW@W@W_@W_@WWW@W@W@W@Wi,@WYZ@WPWPV@VJVJVV@VՄ@VՄ@V@V&@V=@V=@V@V@V@VvV%@V%@V%@VVVVVpVii@V\:@VXEVV@VV@VV@VMV2 @Vf@Vf@Vf@UAUUuUn@UmUjUcUcUUUUUJ@UB@UB@U@U?v@U>$U8U.RU.RU-@U-@U-@U-@UF@UF@UUUUUU U U U@U@U@U@T9TTTTTTT@T@T~T~Tk4Tk4T$TTT@SvSvSvS%@S0S<@S<@S<@SSSSSSS/S/S;@SFS@S@S@S@S@S@Si@S@SSS!@SsZSpSNpS 4@S 4@RRRRRRfhRD!R1R%@R @R @RR|R|R|R|R|RRRRRRRRRRRRR@R@R@R@R@R@R@R@R@R@Q@Q@QQ*@Q?@QQvwQkQIQ5@Q0@Q']Q @PPPP@P@P@P-P@P@P@PDPDPDPDP[PPPPP@P@P@P@PPPPPPPP @P @P @P @P @P @Pf@PPPPP @P @P @P @P@P@P@PPPPPPPP@P@P@PpPpPpP@P@P@P@P@P@P@PP@PP@P@P@P@P@PPXPP{P{P{Pz@PqnPl(PaP`K@P#@Oĺ@O"O"OOO@OO~O@OOO@O@Ou@Ou@Oc+@O]@OYOOdON@OLOLOLOLOLO;@O5O1@ObN@NNNN@NNNj@NN$@N$@NN@N@Nx@Nm@Ng\N[@NTN?N:N:N:NNN|@M{@M{@Mߒ@M@M۝M۝M@MM@M@M3@MM>M>M@MM@M@Mx@MM=M=MwkMwkMv@MtMtMc@Mc@MbSM_MQ0@MJMGMA^@MA^@MA^@M.@M9L!L@L@L@L@LNLNL@L@LA@L@Lk@LYV@LRLI@L7@L(L_LLGKj@KK@KK@KK[K@KK~}@K]KY@KO@KKK/c@K+nK"4@KJJ@JJJkJJ@JJp9JlE@J?r@J0J,@IcIcIzI)@I)@I)@IV@IV@I@I@III@Fabiano Fidêncio - 1.13.3-60Fabiano Fidêncio - 1.13.3-59Fabiano Fidêncio - 1.13.3-58Jakub Hrozek - 1.13.3-57Lukas Slebodnik - 1.13.3-56Lukas Slebodnik - 1.13.3-55Jakub Hrozek - 1.13.3-54Jakub Hrozek - 1.13.3-53Jakub Hrozek - 1.13.3-52Jakub Hrozek - 1.13.3-51Jakub Hrozek - 1.13.3-50Jakub Hrozek - 1.13.3-49Jakub Hrozek - 1.13.3-48Jakub Hrozek - 1.13.3-47Jakub Hrozek - 1.13.3-46Jakub Hrozek - 1.13.3-45Jakub Hrozek - 1.13.3-44Jakub Hrozek - 1.13.3-43Jakub Hrozek - 1.13.3-42Jakub Hrozek - 1.13.3-41Jakub Hrozek - 1.13.3-40Jakub Hrozek - 1.13.3-39Jakub Hrozek - 1.13.3-38Jakub Hrozek - 1.13.3-37Jakub Hrozek - 1.13.3-36Jakub Hrozek - 1.13.3-35Jakub Hrozek - 1.13.3-34Jakub Hrozek - 1.13.3-33Jakub Hrozek - 1.13.3-32Jakub Hrozek - 1.13.3-31Jakub Hrozek - 1.13.3-30Jakub Hrozek - 1.13.3-29Jakub Hrozek - 1.13.3-28Jakub Hrozek - 1.13.3-27Jakub Hrozek - 1.13.3-26Jakub Hrozek - 1.13.3-25Jakub Hrozek - 1.13.3-24Jakub Hrozek - 1.13.3-23Jakub Hrozek - 1.13.3-22Jakub Hrozek - 1.13.3-21Jakub Hrozek - 1.13.3-20Jakub Hrozek - 1.13.3-19Jakub Hrozek - 1.13.3-18Jakub Hrozek - 1.13.3-17Jakub Hrozek - 1.13.3-16Jakub Hrozek - 1.13.3-15Jakub Hrozek - 1.13.3-14Jakub Hrozek - 1.13.3-14Jakub Hrozek - 1.13.3-13Jakub Hrozek - 1.13.3-12Jakub Hrozek - 1.13.3-11Jakub Hrozek - 1.13.3-10Jakub Hrozek - 1.13.3-9Jakub Hrozek - 1.13.3-8Jakub Hrozek - 1.13.3-7Jakub Hrozek - 1.13.3-6Jakub Hrozek - 1.13.3-5Jakub Hrozek - 1.13.3-4Jakub Hrozek - 1.13.3-3Jakub Hrozek - 1.13.3-2Jakub Hrozek - 1.13.3-1Jakub Hrozek - 1.13.2-7Jakub Hrozek - 1.13.2-6Jakub Hrozek - 1.13.2-5Jakub Hrozek - 1.13.2-4Jakub Hrozek - 1.13.2-3Jakub Hrozek - 1.13.2-2Jakub Hrozek - 1.13.2-1Jakub Hrozek - 1.13.1-1Jakub Hrozek - 1.12.4-51Jakub Hrozek - 1.12.4-50Jakub Hrozek - 1.12.4-49Jakub Hrozek - 1.12.4-48Jakub Hrozek - 1.12.4-47Jakub Hrozek - 1.12.4-46Jakub Hrozek - 1.12.4-45Jakub Hrozek - 1.12.4-44Jakub Hrozek - 1.12.4-43Jakub Hrozek - 1.12.4-42Jakub Hrozek - 1.12.4-41Jakub Hrozek - 1.12.4-40Jakub Hrozek - 1.12.4-39Jakub Hrozek - 1.12.4-38Jakub Hrozek - 1.12.4-37Jakub Hrozek - 1.12.4-36Jakub Hrozek - 1.12.4-35Jakub Hrozek - 1.12.4-34Jakub Hrozek - 1.12.4-33Jakub Hrozek - 1.12.4-32Jakub Hrozek - 1.12.4-31Jakub Hrozek - 1.12.4-30Jakub Hrozek - 1.12.4-29Jakub Hrozek - 1.12.4-28Jakub Hrozek - 1.12.4-27Jakub Hrozek - 1.12.4-26Jakub Hrozek - 1.12.4-25Jakub Hrozek - 1.12.4-24Jakub Hrozek - 1.12.4-23Jakub Hrozek - 1.12.4-22Jakub Hrozek - 1.12.4-21Jakub Hrozek - 1.12.4-20Jakub Hrozek - 1.12.4-19Jakub Hrozek - 1.12.4-18Jakub Hrozek - 1.12.4-17Jakub Hrozek - 1.12.4-16Jakub Hrozek - 1.12.4-15Jakub Hrozek - 1.12.4-14Jakub Hrozek - 1.12.4-13Jakub Hrozek - 1.12.4-12Jakub Hrozek - 1.12.4-11Jakub Hrozek - 1.12.4-10Jakub Hrozek - 1.12.4-9Jakub Hrozek - 1.12.4-8Jakub Hrozek - 1.12.4-7Jakub Hrozek - 1.12.4-6Jakub Hrozek - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Jakub Hrozek - 1.12.4-2Jakub Hrozek - 1.12.4-1Jakub Hrozek - 1.11.6-33Jakub Hrozek - 1.11.6-32Jakub Hrozek - 1.11.6-31Jakub Hrozek - 1.11.6-30Jakub Hrozek - 1.11.6-29Jakub Hrozek - 1.11.6-28Jakub Hrozek - 1.11.6-27Jakub Hrozek - 1.11.6-26Jakub Hrozek - 1.11.6-25Jakub Hrozek - 1.11.6-24Jakub Hrozek - 1.11.6-23Jakub Hrozek - 1.11.6-22Jakub Hrozek - 1.11.6-21Jakub Hrozek - 1.11.6-20Jakub Hrozek - 1.11.6-19Jakub Hrozek - 1.11.6-18Jakub Hrozek - 1.11.6-17Jakub Hrozek - 1.11.6-16Jakub Hrozek - 1.11.6-15Jakub Hrozek - 1.11.6-14Jakub Hrozek - 1.11.6-13Jakub Hrozek - 1.11.6-12Jakub Hrozek - 1.11.6-11Jakub Hrozek - 1.11.6-10Jakub Hrozek - 1.11.6-9Jakub Hrozek - 1.11.6-8Jakub Hrozek - 1.11.6-7Jakub Hrozek - 1.11.6-6Jakub Hrozek - 1.11.6-5Jakub Hrozek - 1.11.6-4Jakub Hrozek - 1.11.6-3Jakub Hrozek - 1.11.6-2Jakub Hrozek - 1.11.6-1Jakub Hrozek - 1.11.5.1-4Jakub Hrozek - 1.11.5.1-3Jakub Hrozek - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Jakub Hrozek - 1.9.2-134Jakub Hrozek - 1.9.2-133Jakub Hrozek - 1.9.2-132Jakub Hrozek - 1.9.2-131Jakub Hrozek - 1.9.2-130Jakub Hrozek - 1.9.2-129Jakub Hrozek - 1.9.2-128Jakub Hrozek - 1.9.2-127Jakub Hrozek - 1.9.2-126Jakub Hrozek - 1.9.2-125Jakub Hrozek - 1.9.2-124Jakub Hrozek - 1.9.2-123Jakub Hrozek - 1.9.2-122Jakub Hrozek - 1.9.2-121Jakub Hrozek - 1.9.2-120Jakub Hrozek - 1.9.2-119Jakub Hrozek - 1.9.2-118Jakub Hrozek - 1.9.2-117Jakub Hrozek - 1.9.2-116Jakub Hrozek - 1.9.2-115Jakub Hrozek - 1.9.2-114Jakub Hrozek - 1.9.2-113Jakub Hrozek - 1.9.2-112Jakub Hrozek - 1.9.2-111Jakub Hrozek - 1.9.2-110Jakub Hrozek - 1.9.2-109Jakub Hrozek - 1.9.2-108Jakub Hrozek - 1.9.2-107Jakub Hrozek - 1.9.2-106Jakub Hrozek - 1.9.2-105Jakub Hrozek - 1.9.2-104Jakub Hrozek - 1.9.2-103Jakub Hrozek - 1.9.2-102Jakub Hrozek - 1.9.2-101Jakub Hrozek - 1.9.2-100Jakub Hrozek - 1.9.2-99Jakub Hrozek - 1.9.2-98Jakub Hrozek - 1.9.2-97Jakub Hrozek - 1.9.2-96Jakub Hrozek - 1.9.2-95Jakub Hrozek - 1.9.2-94Jakub Hrozek - 1.9.2-93Jakub Hrozek - 1.9.2-92Jakub Hrozek - 1.9.2-91Jakub Hrozek - 1.9.2-90Jakub Hrozek - 1.9.2-89Jakub Hrozek - 1.9.2-88Jakub Hrozek - 1.9.2-87Jakub Hrozek - 1.9.2-86Jakub Hrozek - 1.9.2-85Jakub Hrozek - 1.9.2-84Jakub Hrozek - 1.9.2-83Jakub Hrozek - 1.9.2-82Jakub Hrozek - 1.9.2-81Jakub Hrozek - 1.9.2-80Jakub Hrozek - 1.9.2-79Jakub Hrozek - 1.9.2-78Jakub Hrozek - 1.9.2-77Jakub Hrozek - 1.9.2-76Jakub Hrozek - 1.9.2-75Jakub Hrozek - 1.9.2-74Jakub Hrozek - 1.9.2-73Jakub Hrozek - 1.9.2-72Jakub Hrozek - 1.9.2-71Jakub Hrozek - 1.9.2-70Jakub Hrozek - 1.9.2-69Jakub Hrozek - 1.9.2-68Jakub Hrozek - 1.9.2-67Jakub Hrozek - 1.9.2-66Jakub Hrozek - 1.9.2-65Jakub Hrozek - 1.9.2-64Jakub Hrozek - 1.9.2-63Jakub Hrozek - 1.9.2-62Jakub Hrozek - 1.9.2-61Jakub Hrozek - 1.9.2-60Jakub Hrozek - 1.9.2-59Jakub Hrozek - 1.9.2-58Jakub Hrozek - 1.9.2-57Jakub Hrozek - 1.9.2-56Jakub Hrozek - 1.9.2-55Jakub Hrozek - 1.9.2-54Jakub Hrozek - 1.9.2-53Jakub Hrozek - 1.9.2-52Jakub Hrozek - 1.9.2-51Jakub Hrozek - 1.9.2-50Jakub Hrozek - 1.9.2-49Jakub Hrozek - 1.9.2-48Jakub Hrozek - 1.9.2-47Jakub Hrozek - 1.9.2-46Jakub Hrozek - 1.9.2-45Jakub Hrozek - 1.9.2-44Jakub Hrozek - 1.9.2-43Jakub Hrozek - 1.9.2-42Jakub Hrozek - 1.9.2-41Jakub Hrozek - 1.9.2-40Jakub Hrozek - 1.9.2-39Jakub Hrozek - 1.9.2-38Jakub Hrozek - 1.9.2-37Jakub Hrozek - 1.9.2-36Jakub Hrozek - 1.9.2-35Jakub Hrozek - 1.9.2-34Jakub Hrozek - 1.9.2-33Jakub Hrozek - 1.9.2-32Jakub Hrozek - 1.9.2-31Jakub Hrozek - 1.9.2-30Jakub Hrozek - 1.9.2-29Jakub Hrozek - 1.9.2-28Jakub Hrozek - 1.9.2-27Jakub Hrozek - 1.9.2-26Jakub Hrozek - 1.9.2-25Jakub Hrozek - 1.9.2-24Jakub Hrozek - 1.9.2-23Jakub Hrozek - 1.9.2-22Jakub Hrozek - 1.9.2-21Jakub Hrozek - 1.9.2-20Jakub Hrozek - 1.9.2-20Jakub Hrozek - 1.9.2-19Jakub Hrozek - 1.9.2-18Jakub Hrozek - 1.9.2-17Jakub Hrozek - 1.9.2-16Jakub Hrozek - 1.9.2-15Jakub Hrozek - 1.9.2-14Jakub Hrozek - 1.9.2-13Jakub Hrozek - 1.9.2-12Jakub Hrozek - 1.9.2-11Jakub Hrozek - 1.9.2-10Jakub Hrozek - 1.9.2-9Jakub Hrozek - 1.9.2-8Jakub Hrozek - 1.9.2-7Jakub Hrozek - 1.9.2-6Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-3Jakub Hrozek - 1.9.0-2Jakub Hrozek - 1.9.0-1.rc1Jakub Hrozek - 1.8.0-33Stephen Gallagher - 1.8.0-32Stephen Gallagher - 1.8.0-31Stephen Gallagher - 1.8.0-30Stephen Gallagher - 1.8.0-29Stephen Gallagher - 1.8.0-28Stephen Gallagher - 1.8.0-27Stephen Gallagher - 1.8.0-26Stephen Gallagher - 1.8.0-25Stephen Gallagher - 1.8.0-24Stephen Gallagher - 1.8.0-23Stephen Gallagher - 1.8.0-22Stephen Gallagher - 1.8.0-21Stephen Gallagher - 1.8.0-20Stephen Gallagher - 1.8.0-18Stephen Gallagher - 1.8.0-17Stephen Gallagher - 1.8.0-15Stephen Gallagher - 1.8.0-12Stephen Gallagher - 1.8.0-11Stephen Gallagher - 1.8.0-10Stephen Gallagher - 1.8.0-9Stephen Gallagher - 1.8.0-8Stephen Gallagher - 1.8.0-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5Stephen Gallagher - 1.8.0-4.beta3Stephen Gallagher - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-2.beta2Stephen Gallagher - 1.5.1-68Stephen Gallagher - 1.5.1-67Stephen Gallagher - 1.5.1-66Stephen Gallagher - 1.5.1-65Stephen Gallagher - 1.5.1-64Stephen Gallagher - 1.5.1-63Stephen Gallagher - 1.5.1-62Stephen Gallagher - 1.5.1-61Stephen Gallagher - 1.5.1-60Stephen Gallagher - 1.5.1-59Stephen Gallagher - 1.5.1-58Stephen Gallagher - 1.5.1-57Stephen Gallagher - 1.5.1-56Stephen Gallagher - 1.5.1-55Stephen Gallagher - 1.5.1-53Stephen Gallagher - 1.5.1-52Stephen Gallagher - 1.5.1-51Stephen Gallagher - 1.5.1-50Stephen Gallagher - 1.5.1-49Stephen Gallagher - 1.5.1-48Stephen Gallagher - 1.5.1-47Stephen Gallagher - 1.5.1-46Stephen Gallagher - 1.5.1-45Stephen Gallagher - 1.5.1-44Stephen Gallagher - 1.5.1-43Stephen Gallagher - 1.5.1-42Stephen Gallagher - 1.5.1-41Stephen Gallagher - 1.5.1-40Stephen Gallagher - 1.5.1-39Stephen Gallagher - 1.5.1-38Stephen Gallagher - 1.5.1-37Stephen Gallagher - 1.5.1-36Stephen Gallagher - 1.5.1-35Stephen Gallagher - 1.5.1-34Stephen Gallagher - 1.5.1-33Stephen Gallagher - 1.5.1-32Stephen Gallagher - 1.5.1-31Stephen Gallagher - 1.5.1-30Stephen Gallagher - 1.5.1-29Stephen Gallagher - 1.5.1-28Stephen Gallagher - 1.5.1-27Stephen Gallagher - 1.5.1-26Stephen Gallagher - 1.5.1-25Stephen Gallagher - 1.5.1-24Stephen Gallagher - 1.5.1-23Stephen Gallagher - 1.5.1-21Stephen Gallagher - 1.5.1-20Stephen Gallagher - 1.5.1-17Stephen Gallagher - 1.5.1-16Stephen Gallagher - 1.5.1-15Stephen Gallagher - 1.5.1-14Stephen Gallagher - 1.5.1-13Stephen Gallagher - 1.5.1-12Stephen Gallagher - 1.5.1-11Stephen Gallagher - 1.5.1-10Stephen Gallagher - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Stephen Gallagher - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.2.1-28.4Stephen Gallagher - 1.2.1-36Stephen Gallagher - 1.2.1-35Stephen Gallagher - 1.2.1-28.3Stephen Gallagher - 1.2.1-34Stephen Gallagher - 1.2.1-28.2Stephen Gallagher - 1.2.1-33Stephen Gallagher - 1.2.1-28.1Stephen Gallagher - 1.2.1-32Stephen Gallagher - 1.2.1-29Stephen Gallagher - 1.2.1-28Stephen Gallagher - 1.2.1-27Stephen Gallagher - 1.2.1-26Stephen Gallagher - 1.2.1-23Stephen Gallagher - 1.2.1-21Stephen Gallagher - 1.2.1-20Stephen Gallagher - 1.2.1-19Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-14Stephen Gallagher - 1.2.0-13Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11.1Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Related: rhbz#1442703 - Smart Cards: Certificate in the ID View - Related: rhbz# 1401546 - Please back-port fast failover from sssd 1.14 on RHEL 7 into sssd 1.13 on RHEL 6- Resolves: rhbz#1326007 - Memory cache corruption when rsync and/or tar to copy owner and group info from LDAP - Resolves: rhbz#1442703 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1507435 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-6.10] - Resolves: rhbz#1487040 - sssd does not evaluate AD UPN suffixes which results in failed user logins- Resolves: rhbz#1421057 - pam_sss crashes in do_pam_conversation if no conversation function is provided by the client app - Resolves: rhbz#1487040 - sssd does not evaluate AD UPN suffixes which results ini failed user logins - Resolves: rhbz#1487944 - ABRT crash - /usr/libexec/sssd/sssd_nss - Resolves: rhbz#1489485 - sssd is not pulling groups in a trusted domain, with the Global scope- Resolves: rhbz#1438360 - The originalMemberOf attribute disappears from the cache, causing intermittent HBAC issues- Resolves: rhbz#1404697 - SSSD does not skip GPO if no gpcFunctionalityVersion present - Resolves: rhbz#1374813 - SSSD fails to process GPO from Active Directory- Resolves: rhbz#1415785 - ldap_child does not remove temporary files when it's killed with SIGTERM- Apply several more smartcard-related patches. - Related: rhbz#1300421 - Screen locks and smart card is removed - must show a message to insert the correct smartcard- Resolves: rhbz#1400643 - sssd prevents sudo from getting data from LDAP- Resolves: rhbz#1393592 - SSH-CERT: always initialize cert_verify_opts- Revert the ding-libs requirement - Related: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Related: rhbz#1369921 - Members of nested netgroups configured in IdM cannot be seen by getent on clients- Require the matching version of ding-libs - Related: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Fix a coverity warning - Related: rhbz#1382395 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1382395 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1369921 - Members of nested netgroups configured in IdM cannot be seen by getent on clients- Resolves: rhbz#1324428 - [RFE] Discover forest's root SID even if subdomains_provider = none- Resolves: rhbz#1367802 - using overides causes segfault in libldb- Resolves: rhbz#1329378 - pam_sss set KRB5CCNAME with sudo logins- Resolves: rhbz#1382603 - autofs map resolution doesn't work offline- Resolves: rhbz#1339986 - [sssd-ldap] man page needs attention- Resolves: rhbz#1321884 - IPA sudo: support the externalUser attribute- Resolves: rhbz#1299994 - ssh client checks only the first certificate on a smartcard when the card has multiple certs - Resolves: rhbz#1300421 - Screen locks and smart card is removed - must show a message to insert the correct smartcard - Resolves: rhbz#1372681 - ssh with Smartcards - skip invalid certificates- Resolves: rhbz#1329648 - Protocol error with IPA on RHEL-6 - Resolves: rhbz#1329647 - IPA view: view name not stored properly with default FreeIPA installation- Resolves: rhbz#1339986 - [sssd-ldap] man page needs attention- Resolves: rhbz#1327272 - local overrides: issues with sub-domain users and mixed case names- Resolves: rhbz#1293168 - Inconsistent user synching between IPA and AD- Resolves: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Resolves: rhbz#1377782 - sssd is looking at a server in the GC of a subdomain, not the root domain.- Resolves: rhbz#1365218 - SSSD does not fail over to next GC- Resolves: rhbz#1367435 - Intermittent sssd auth failures- Resolves: rhbz#1369079 - sssd runs out of available child slots and starts queuing requests in proxy mode- Resolves: rhbz#1338619 - segmentation fault in sssd after upgrade to sssd-1.13.3-22.el6.x86_64 when upgrading cache- Resolves: rhbz#1324107 - GPO: Access denied after blocking connection to AD.- Resolves: rhbz#1293168 - Inconsistent user synching between IPA and AD- Resolves: rhbz#1340927 - sssd-common requires libnfsidmap- Resolves: rhbz#1340176 - The AD keytab renewal task leaks a file descriptor- Resolves: rhbz#1335400 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1336453 - sssd_be doesn't terminate forked child process if adcli is not installed- Resolves: rhbz#1312062 - sssd does not pass LDAP rules to sudo- Resolves: rhbz#1313940 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo- Actually apply patches from previous build - Resolves: rhbz#1313940 - sudorule not working with ipa sudo_provider- Resolves: rhbz#1313940 - sudorule not working with ipa sudo_provider- Resolves: rhbz#1209600 - Getting ERROR (getpwnam() failed): Broken pipe with 1.11.6- Backport of a more minimal dependency patch to avoid changes to AD provider behaviour - Related: rhbz#1264705 - Allow SSSD to notify user of denial due to AD account lockout- Resolves: rhbz#1308939 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user- Require a newer selinux-policy to avoid issues when prompting for SC PIN - Related: rhbz#1299066 - smartcard login does not prompt for pin when ocsp checking is enabled (default config)- Resolves: rhbz#1264705 - Allow SSSD to notify user of denial due to AD account lockout- Resolves: rhbz#1259687 - sssd_nss memory usage keeps growing on sssd-1.12.4-47.el6.x86_64 (RHEL6.7) when trying to retrieve non-existing netgroups- Update sssd-ldap man page for the recent ID mapping changes - Related: rhbz#1268902 - SSSD doesn't set the ID mapping range automatically- Resolves: rhbz#1295883 - refresh_expired_interval stops sss_cache from working- Resolves: rhbz#1268902 - SSSD doesn't set the ID mapping range automatically- Resolves: rhbz#1298253 - Screen lock prompts for smartcard user password and not smartcard pin when logged in using smartcard pin- Resolves: rhbz#1292458 - sssd_be AD segfaults on missing A record- Resolves: rhbz#1262981 - sssd dereference processing failed : Input/output error- Resolves: rhbz#1290761 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs- Resolves: rhbz#1244957 - [RFE] SUDO: Support the IPA schema- Resolves: rhbz#1298634 - Cannot retrieve users after upgrade from 1.12 to 1.13- Resolves: rhbz#1287807 - SRV lookup for KDC servers doesn't work- Resolves: rhbz#1273802 - ad_site parameter does not work- Fix memory leak in the NFS plugin - Related: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - Resolves: rhbz#1296620 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1283898 - MAN: Clarify that subdomains always use service discovery- Rebase to 1.13.3 - Remove setuid bit from proxy_child, RHEL-6 doesn't support running SSSD as a non-privileged user - Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8- Don't own files as the SSSD user - Resolves: rhbz#1289482 - warning: user sssd does not exist - using root- Resolves: rhbz#1279971 - groups get deleted from the cache- The p11_child doesn't have to run privileged anymore, remove the setuid bit - Related: rhbz#1270027 - [RFE] Support for smart cards- Resolves: rhbz#1266108 - Check next certificate on smart card if first is not valid - Also enable OCSP checks- Resolves: rhbz#1285852 - sssd: [sysdb_add_user] (0x0400): Error: 17 (File exists)- Silence compilation warnings and Coverity issues - Related: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8- Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - Squash in packaging review changes by lslebodn@redhat.com- Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - The rebase also resolves the following bugzillas: - Resolves: rhbz#1270029 - [RFE] Add a way to lookup users based on CAC identity certificates - Resolves: rhbz#1270027 - [RFE] Support for smart cards - Resolves: rhbz#1269422 - [FEAT] UID and GID mapping on individual clients - Resolves: rhbz#1269421 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#1265429 - If the site discovery fails, ad-site option is not taken into account. - Resolves: rhbz#1254193 - Fix for cyclic dependencies between sssd-{krb5,}-common - Resolves: rhbz#1247997 - [IPA/IdM] sudoOrder not honored as expected - Resolves: rhbz#1237142 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1232632 - Kerberos-based providers other than krb5 do not queue requests - Resolves: rhbz#1227804 - Group members are not turned into ghost entries when the user is purged from the SSSD cache - Resolves: rhbz#1227685 - sssd with ldap backend throws error domain log - Resolves: rhbz#1221365 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1215195 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1196204 - sssd cache holding gid values for nss, but not the alpha group name representation - Resolves: rhbz#1194039 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD- Resolves: rhbz#1266404 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1264524 - SSSD POSIX attribute check is too strict- Resolves: rhbz#1255285 - cleanup_groups should sanitize dn of groups- Resolves: rhbz#1251349 - sysdb sudo search doesn't escape special characters- Resolves: rhbz#1232738 - Cache is not updated after user is deleted from ldap server- Resolves: rhbz#1227860 - Provide a way to disable the cleanup task - Resolves: rhbz#1227863 - ignore_group_members doesn't work for subdomains- Resolves: rhbz#1226834 - id lookup for non-root domain users doesn't return all groups on first attempt- Resolves: rhbz#1225614 - IPA enumeration provider crashes- Resolves: rhbz#1212610 - sssd ad groups work intermittently- Resolves: rhbz#1215765 - sssd nss responder gets wrong number of secondary groups- Resolves: rhbz#1221358 - SSSD doesn't work with ID mapping and disabled subdomains- Resolves: rhbz#1219844 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust- Resolves: rhbz#1216094 - /usr/libexec/sssd/selinux_child crashes and gets avc denial when ssh- Include several upstream fixes related to ID views - Resolves: rhbz#1215195 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1213947 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1213822 - Overrides with --login work in second attempt- Resolves: rhbz#1217328 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set- Resolves: rhbz#1212387 - sssd_be segfault id_provider = ad src/providers/ad/ad_gpo.c:843- Resolves: rhbz#1213940 - Overridde with --login fails trusted adusers group membership resolution- Resolves: rhbz#1170910 - SSSD should not fail authentication when only allow rules are used- Resolves: rhbz#1213716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1213822 - Overrides with --login work in second attempt- Resolves: rhbz#1212017 - Sudo responder does not respect filter_users and filter_groups- Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only- Related: rhbz#1211728 - Only set the selinux context if the context differs from the local one- Package the localauth plugin - Related: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Resolves: rhbz#1207720 - id lookup resolves "Domain Local" group and errors appear in domain log- BuildRequire the proper libkrb5 version for correct localauth plugin build - Related: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Resolves: rhbz#1194367 - sssd_be dumping core- Resolves: rhbz#1206121 - ldap_access_order=ppolicy: Explicitly mention in manpage that unsupported time specification will lead to sssd denying access- Resolves: rhbz#1205382 - Properly handle AD's binary objectGUID- Resolves: rhbz#1205716 - Installing sssd-common-1.12.4-18.el6 might install with wrong user account (root)- Fix a typo in DEBUG message - Related: rhbz#1173198 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires- Handle TTL=0 in SRV queries correctly - Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query- Cherry-pick unit test changes from upstream to allow cherry-picking sssd-1-12 patches - Remove unused LDAP provider code to avoid static analyser warnings - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1206092 - sssd crashes intermittently in GPO code- Resolves: rhbz#1202728 - sssd-ad requires samba3, but ipa-server-trust-ad requires samba4- Resolves: rhbz#1203630 - SSSD doesn't own the GPO cache directory- Fix warning in SELinux code - Handle setups with empty default and no SELinux maps - Related: rhbz#1194302 - With empty ipaselinuxusermapdefault security context on client is staff_u - Resolves: rhbz#1202305 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605 - Resolves: rhbz#1201847 - SSSD downloads too much information when fetching information about groups- Fix PAM responder initgroups cache for subdomain users - Log extop failures better - Related: rhbz#1168344 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Fix internal error codes broken when fixing rhbz#1036745 - Related: rhbz#1036745 - [RFE] Allow SSSD to issue shadow expiration warning even if alternate authentication method is used- Resolves: rhbz#1200093 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything- Fix Coverity warning in ldap_child - Add better debugging - Related: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1098147 - [RFE] Implement background refresh for users, groups or other cache objects- Resolves: rhbz#1173198 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires- Initialize a pointer in ldap_child to NULL - Resolves: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Relax the ldb requirement - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1194302 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query- Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query - Rebuild against latest krb5, add a versioned BuildRequires - Resolves: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Related: rhbz#1036745 - [RFE] Allow SSSD to issue shadow expiration warning even if alternate authentication method is used- Do not mark the selinux_child helper as setuid, we don't support rootless SSSD in 6.7 - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1168347 - Rebase sssd to 1.12.x - The rebase resolves the following RHEL bugzillas - Resolves: rhbz#1172865 - sssd.conf(5) man page gives bad advice about domains parameter - Resolves: rhbz#1172494 - PAC: krb5_pac_verify failures should not be fatal (backport fix from upstream) - Resolves: rhbz#1171782 - [RFE]: SSSD should preserve case for user uid field - Resolves: rhbz#1170910 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1168377 - [RFE] User's home directories and shells are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1168363 - [RFE] Add domains= option to pam_sss - Resolves: rhbz#1168344 - [RFE] ID Views: Support migration from the sync solution to the trust solution - Resolves: rhbz#1161564 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1148582 - inconsistent group information when multiple ad domain sections are configured in sssd - Resolves: rhbz#1140909 - sssd.conf man page missing subdomains_provider ad support - Resolves: rhbz#1139878 - SSSD connection terminated after failing anonymous bind to IBM Tivoli Directory Server - Resolves: rhbz#1135838 - Man sssd-ldap shows parameter ldap_purge_cache_timeout with "Default: 10800 (12 hours)" - Resolves: rhbz#1135432 - Dereference code errors out when dereferencing entries protected by ACIs - Resolves: rhbz#1134942 - sssd does not recognize Windows server 2012 R2's LDAP as AD - Resolves: rhbz#1123291 - automount segfaults in sss_nss_check_header - Resolves: rhbz#1088402 - [RFE] Allow login through SSSD using multiple attributes- Resolves: rhbz#1154042 - RHEL6.6 sssd (1.11) doesn't return all group memberships against an IPA server- Resolves: rhbz#1160713 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1141814 - Password expiration policies are not being enforced by SSSD- Resolves: rhbz#1139044 - RHEL6.6 ipa user private group not found- Resolves: rhbz#1103487 - CVE-2014-0249 - sssd: incorrect expansion of group membership when encountering a non-POSIX group- Resolves: rhbz#1125187 - simple_allow_groups does not lookup groups from other AD domains- Resolves: rhbz#1127270 - sssd connect to ipa-server is long- Resolves: rhbz#1130017 - Saving group membership fails if provider is AD, POSIX attributes are used and primary group contains the user as a member- Resolves: rhbz#1111528 - Expired shadow policy user(shadowLastChange=0) is not prompted for password change- Resolves: rhbz#1132361 - use-after-free in dyndns code- Resolves: rhbz#1099290: RFE: Be able to configure sssd to honor openldap account lock to restrict access via ssh key- Use the correct sudo iterator - Related: rhbz#1118336 - sudo: invalid sudoHost filter with asterisk- Add notes about offline mode to sssd.conf - Related: rhbz#1110226 - Requests queued during transition from offline to online mode- Resolves: rhbz#1127278 - Auth fails when space in username is replaced with character set by override_default_whitespace- Resolves: rhbz#1127757 - sssd can't retrieve sudo rules when using the "default_domain_suffix" option- Resolves: rhbz#1127265 - Problems with tokengroups and ldap_group_search_base- Resolves: rhbz#1126636 - RHEL6.6 sssd not running after upgrade- Resolves: rhbz#1128612 - IFP: FQDN lookups are broken- Resolves: rhbz#1118336 - sudo: invalid sudoHost filter with asterisk- Resolves: rhbz#1110226 - Requests queued during transition from offline to online mode- Resolves: rhbz#1122873 - Failover does not always happen from SRV to hostname resolution(via /etc/hosts) - Remove spurious systemctl call on %postun- Resolves: rhbz#1111317 - [RFE] Add option for sssd to replace space with specified character in LDAP group- Resolves: rhbz#1109188 - dereferencing control failure against openldap server- Resolves: rhbz#1084532 - sssd_sudo process segfaults- Resolves: rhbz#1122158 - ad: group membership is empty when id mapping is off and tokengroups are enabled- Resolves: rhbz#1118541 - Floating point exception using ldap- Resolves: rhbz#1042922 - [RFE] Add fallback to sudoRunAs when sudoRunAsUser is not defined and no ldap_sudorule_runasuser mapping has been defined in SSSD- Resolves: rhbz#1120508 - tokengroups do not work with id_provider=ldap- Fix potential NULL dereference in IFP code - Related: rhbz#1110369 - sssd is started before messagebus, making sssd-ifp fail- BuildRequire the latest libini_config - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Resolves: rhbz#1110369 - sssd is started before messagebus, making sssd-ifp fail- Resolves: rhbz#1104145 - public key validator is too strict and does not allow newlines anywhere in the public key string, not even at the end- Rebase to 1.11.6 - Resolves: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Rebuild against new ding-libs - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Backport the InfoPipe patches needed for Sat6 integration - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Resolves: #1085412 - SSSD Crashes when storage experiences high latency- Resolves: #1051164 - Rebase SSSD to 1.11+ in RHEL6Resolves: #1036168 - sssd can't retrieve auto.master when using the "default_domain_suffix"- Resolves: #1065534 - SSSD pam module accepts usernames with leading spaces- Resolves: #1038098 - sssd_nss grows memory footprint when netgroups are requested- Allow combination of proxy id backend and LDAP auth backend - Resolves: #1025813 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Inherit UID limits for subdomains - Resolves: #1020905 - Creating system accounts on a IdM client takes up to 10 minutes when AD trust is configured in the IdM.- Do not crash when LDAP disconnects while a search is still in progress - Resolves: #1019979 - sssd_be segfault when authenticating against active directory- More upstream fixes to prevent memcache crashes - Related: #997406 - sssd_nss core dumps under load- Resolves: #1002929 - sssd_be segfaults if IPA dynamic DNS update times out- Make IPA SELinux provider aware of subdomain users - A better version of already committed patch - Resolves: #954342 - In IPA AD trust setup, the sssd logs throws 'sysdb_search_user_by_name failed' error when AD user tries to login via ipa client.- Resolves: #997406 - sssd_nss core dumps under load - Resolves: #984814 - sssd_nss terminated with segmentation fault- Resolves: #1002161 - large number of sudo rules results in error - Unable to create response: Invalid argument- Silence restorecon on clean install - Resolves: #987456 - RHEL6 sssd upgrade restorecon workaround for /var/lib/sss/mc context- Make IPA SELinux provider aware of subdomain users - Resolves: #954342 - In IPA AD trust setup, the sssd logs throws 'sysdb_search_user_by_name failed' error when AD user tries to login via ipa client.- Print password complexity hint when password change fails with constraint violation - Related: #983028 - passwd returns "Authentication token manipulation error" when entering wrong current password- Resolves: #983028 - passwd returns "Authentication token manipulation error" when entering wrong current password- Resolves: #948830 - sssd do too many disk writes causing delay in "getent netgroup allmachines-netgroup" nested netgroups.- Resolves: #984814 - sssd_nss terminated with segmentation fault- Resolves: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- Resolves: #963235 - sssd_be crashing with nested ldap groups- Apply a forgotten dependency for patch #254 - Related: #916997 - getgrnam / getgrgid for large user groups is too slow due to range retrieval functionality - Add two fixes for better handling of faulty SRV processing - Related: #954275 - sssd fails connect to IPA server during boot when spanning tree is enabled in network router. - Remove enumerate=true from example in man page - Related: #988381 - clarify the disadvantages of enumeration in sssd.conf- Resolves: #914433 - sssd pam write_selinux_login_file creating the temp file for SELinux data failed- Resolves: #916997 - getgrnam / getgrgid for large user groups is too slow due to range retrieval functionality- Resolves: #918394 - sssd etas 99% CPU and runs out of file descriptors when clearing cache- Resolves: #924113 - man sssd-sudo has wrong title- Resolves: #924397 - document what does access_provider=ad do- Use permissive control when adding ghost users - Resolves: #928797 - cyclic group memberships may not work depending on order of operations- Set correct state of SRV servers on resolving error - Resolves: #954275 - sssd fails connect to IPA server during boot when spanning tree is enabled in network router.- Resolves: #954323 - SSSD doesn't display warning for last grace login.- Format patch to configure sysv script differently - RHEL-6 patch(1) apparently doesn't like the output of git format-patch -M -C and doesn't properly copy files on renames - Resolves: #971435 - Enhance sssd init script so that it would source a configuration.- Resolves: #973345 - SSSD service randomly dies- Resolves: #971435 - Enhance sssd init script so that it would source a configuration- Resolves: #961356 - SUDO is not working for users from trusted AD domain- Resolves: #970519 - [RFE] Add support for suppressing group members- Resolves: #976273 - [RFE] Add a new override_homedir expansion for the "original value"- Resolves: #978966 - sudoHost mismatch response is incorrect sometimes- Clarify the min_id/max_id limits further - Resolves: #978994 - SSSD filter out ldap user/group if uid/gid is zero- Resolves: #979046 - sssd_be goes to 99% CPU and causes significant login delays when client is under load- Resolves: #986379 - sss_cache -N/-n should invalidate the hash table in sssd_nss- Resolves: #988525 - sssd fails instead of skipping when a sudo ldap filter returns entries with multiple CNs- Mention that enumeration should be discouraged - Resolves: #988381 - clarify the disadvantages of enumeration in sssd.conf- Call restorecon on memcache files to force the right context on upgrades - Resolves: #987456 - RHEL6 sssd upgrade restorecon workaround for /var/lib/sss/mc context- Resolves: #987479 - libsss_sudo should depend on sudo package with sssd support- Resolves: #951086 - sssd_pam segfaults if sssd_be is stuck- Resolves: #967636 - SSSD frequently fails to return automount maps from LDAP- Resolves: #953165 - Enabling enumeration causes sssd_be process to utilize 100% of the CPU- Resolves: #906398 - sssd_be crashes sometimes- Resolves: #950874: Simple access control always denies uppercased users in case insensitive domain- Resolves: #921454: Resolve local group members in LDAP groups- Resolves: rhbz#911299 - sssd: simple access provider flaw prevents intended ACL use when client to an AD provider- Fix pwd_expiration_warning=0 - Resolves: rhbz#911329 - pwd_expiration_warning has wrong default for Kerberos- Resolves: rhbz#911329 - pwd_expiration_warning has wrong default for Kerberos- Resolves: rhbz#872827 - Serious performance regression in sssd- Resolves: rhbz#888614 - Failure in memberof can lead to failed database update- Resolves: rhbz#903078 - TOCTOU race conditions by copying and removing directory trees- Resolves: rhbz#903078 - Out-of-bounds read flaws in autofs and ssh services responders- Resolves: rhbz#902716 - Rule mismatch isn't noticed before smart refresh on ppc64 and s390x- Resolves: rhbz#896476 - SSSD should warn when pam_pwd_expiration_warning value is higher than passwordWarning LDAP attribute.- Resolves: rhbz#902436 - possible segfault when backend callback is removed- Resolves: rhbz#895132 - Modifications using sss_usermod tool are not reflected in memory cache- Resolves: rhbz#894302 - sssd fails to update to changes on autofs maps- Resolves: rhbz894381 - memory cache is not updated after user is deleted from ldb cache- Resolves: rhbz895615 - ipa-client-automount: autofs failed in s390x and ppc64 platform- Resolves: rhbz#894997 - sssd_be crashes looking up members with groups outside the nesting limit- Resolves: rhbz#895132 - Modifications using sss_usermod tool are not reflected in memory cache- Resolves: rhbz#894428 - wrong filter for autofs maps in sss_cache- Resolves: rhbz#894738 - Failover to ldap_chpass_backup_uri doesn't work- Resolves: rhbz#887961 - AD provider: getgrgid removes nested group memberships- Resolves: rhbz#878583 - IPA Trust does not show secondary groups for AD Users for commands like id and getent- Resolves: rhbz#874579 - sssd caching not working as expected for selinux usermap contexts- Resolves: rhbz#892197 - Incorrect principal searched for in keytab- Resolves: rhbz#891356 - Smart refresh doesn't notice "defaults" addition with OpenLDAP- Resolves: rhbz#878419 - sss_userdel doesn't remove entries from in-memory cache- Resolves: rhbz#886848 - user id lookup fails for case sensitive users using proxy provider- Resolves: rhbz#890520 - Failover to krb5_backup_kpasswd doesn't work- Resolves: rhbz#874618 - sss_cache: fqdn not accepted- Resolves: rhbz#889182 - crash in memory cache- Resolves: rhbz#889168 - krb5 ticket renewal does not read the renewable tickets from cache- Resolves: rhbz#886091 - Disallow root SSH public key authentication - Add default section to switch statement (Related: rhbz#884666)- Resolves: rhbz#886038 - sssd components seem to mishandle sighup- Resolves: rhbz#888800 - Memory leak in new memcache initgr cleanup function- Resolves: rhbz#888614 - Failure in memberof can lead to failed database update- Resolves: rhbz#885078 - sssd_nss crashes during enumeration if the enumeration is taking too long- Related: rhbz#875851 - sysdb upgrade failed converting db to 0.11 - Include more debugging during the sysdb upgrade- Resolves: rhbz#877972 - ldap_sasl_authid no longer accepts full principal- Resolves: rhbz#870045 - always reread the master map from LDAP - Resolves: rhbz#876531 - sss_cache does not work for automount maps- Resolves: rhbz#884666 - sudo: if first full refresh fails, schedule another first full refresh- Resolves: rhbz#880956 - Primary server status is not always reset after failover to backup server happened - Silence a compilation warning in the memberof plugin (Related: rhbz#877974) - Do not steal resolv result on error (Related: rhbz#882076)- Resolves: rhbz#882923 - Negative cache timeout is not working for proxy provider- Resolves: rhbz#884600 - ldap_chpass_uri failover fails on using same hostname- Resolves: rhbz#858345 - pam_sss(crond:account): Request to sssd failed. Timer expired- Resolves: rhbz#878419 - sss_userdel doesn't remove entries from in-memory cache- Resolves: rhbz#880176 - memberUid required for primary groups to match sudo rule- Resolves: rhbz#885105 - sudo denies access with disabled ldap_sudo_use_host_filter- Resolves: rhbz#883408 - Option ldap_sudo_include_regexp named incorrectly- Resolves: rhbz#880546 - krb5_kpasswd failover doesn't work - Fix the error handler in sss_mc_create_file (Related: #789507)- Resolves: rhbz#882221 - Offline sudo denies access with expired entry_cache_timeout - Fix several bugs found by Coverity and clang: - Check the return value of diff_gid_lists (Related: #869071) - Move misplaced sysdb assignment (Related: #827606) - Remove dead assignment (Related: #827606) - Fix copy-n-paste error in the memberof plugin (Related: #877974)- Resolves: rhbz#882923 - Negative cache timeout is not working for proxy provider - Link sss_ssh_authorizedkeys and sss_ssh_knowhostsproxy with the client libraries (Related: #870060) - Move sss_ssh_knownhosts documentation to the correct section (Related: #870060)- Resolves: rhbz#884480 - user is not removed from group membership during initgroups - Fix incorrect synchronization in mmap cache (Related: #789507)- Resolves: rhbz#883336 - sssd crashes during start if id_provider is not mentioned- Resolves: rhbz#882290 - arithmetic bug in the SSSD causes netgroup midpoint refresh to be always set to 10 seconds- Resolves: rhbz#877974 - updating top-level group does not reflect ghost members correctly - Resolves: rhbz#880159 - delete operation is not implemented for ghost users- Resolves: rhbz#881773 - mmap cache needs update after db changes- Resolves: rhbz#875677 - password expiry warning message doesn't appear during auth - Fix potential NULL dereference when skipping built-in AD groups (Related: rhbz#874616) - Add missing parameter to DEBUG message (Related: rhbz#829742)- Resolves: rhbz#882076 - SSSD crashes when c-ares returns success but an empty hostent during the DNS update - Do not version libsss_sudo, it's not supposed to be linked against, but dlopened (Related: rhbz#761573)- Resolves: rhbz#880140 - sssd hangs at startup with broken configurations- Resolves: rhbz#878420 - SIGSEGV in IPA provider when ldap_sasl_authid is not set- Resolves: rhbz#874616 - Silence the DEBUG messages when ID mapping code skips a built-in group- Resolves: rhbz#824244 - sssd does not warn into sssd.log for broken configurations- Resolves: rhbz#874673 - user id lookup fails using proxy provider - Fix a possibly uninitialized variable in the LDAP provider - Related: rhbz#877130- Resolves: rhbz#878262 - ipa password auth failing for user principal name when shorter than IPA Realm name - Resolves: rhbz#871843 - Nested groups are not retrieved appropriately from cache- Resolves: rhbz#870238 - IPA client cannot change AD Trusted User password- Resolves: rhbz#877972 - ldap_sasl_authid no longer accepts full principal- Resolves: rhbz#861075 - SSSD_NSS failure to gracefully restart after sbus failure- Resolves: rhbz#877354 - ldap_connection_expire_timeout doesn't expire ldap connections- Related: rhbz#877126 - Bump the release tag- Resolves: rhbz#877126 - subdomains code does not save the proper user/group name- Resolves: rhbz#877130 - LDAP provider fails to save empty groups - Related: rhbz#869466 - check the return value of waitpid()- Resolves: rhbz#870039 - sss_cache says 'Wrong DB version'- Resolves: rhbz#875740 - "defaults" entry ignored- Resolves: rhbz#875738 - offline authentication failure always returns System Error- Resolves: rhbz#875851 - sysdb upgrade failed converting db to 0.11- Resolves: rhbz#870278 - ipa client setup should configure host properly in a trust is in place- Resolves: rhbz#871160 - sudo failing for ad trusted user in IPA environment- Resolves: rhbz#870278 - ipa client setup should configure host properly in a trust is in place- Resolves: rhbz#869678 - sssd not granting access for AD trusted user in HBAC rule- Resolves: rhbz#872180 - subdomains: Invalid sub-domain request type - Related: rhbz#867933 - invalidating the memcache with sss_cache doesn't work if the sssd is not running- Resolves: rhbz#873988 - Man page issue to list 'force_timeout' as an option for the [sssd] section- Resolves: rhbz#873032 - Move sss_cache to the main subpackage- Resolves: rhbz#873032 - Move sss_cache to the main subpackage - Resolves: rhbz#829740 - Init script reports complete before sssd is actually working - Resolves: rhbz#869466 - SSSD starts multiple processes due to syntax error in ldap_uri - Resolves: rhbz#870505 - sss_cache: Multiple domains not handled properly - Resolves: rhbz#867933 - invalidating the memcache with sss_cache doesn't work if the sssd is not running - Resolves: rhbz#872110 - User appears twice on looking up a nested group- Resolves: rhbz#871576 - sssd does not resolve group names from AD - Resolves: rhbz#872324 - pam: fd leak when writing the selinux login file in the pam responder - Resolves: rhbz#871424 - authconfig chokes on sssd.conf with chpass_provider directive- Do not send SIGKILL to service right after sending SIGTERM - Resolves: #771975 - Fix the initial sudo smart refresh - Resolves: #869013 - Implement password authentication for users from trusted domains - Resolves: #869071 - LDAP child crashed with a wrong keytab - Resolves: #869150 - The sssd_nss process grows the memory consumption over time - Resolves: #869443- BuildRequire selinux-policy so that selinux login support is built in - Resolves: #867932- Do not segfault if namingContexts contain no values or multiple values - Resolves: rhbz#866542- Fix the "ca" translation of the sssd-simple manual page - Related: rhbz#827606 - Rebase SSSD to 1.9 in 6.4- New upstream release 1.9.2- Rebase to 1.9.1- Require the latest libldb- Rebase to 1.9.0 - Resolves: rhbz#827606 - Rebase SSSD to 1.9 in 6.4- Rebase to 1.9.0 RC1 - Resolves: rhbz#827606 - Rebase SSSD to 1.9 in 6.4 - Bump the selinux-policy version number to pull in required fixes- Resolves: rhbz#840089 - Update the shadowLastChange attribute with days since the Epoch, not seconds- Fix protocol break for services map - Related: rhbz#825028 - Service lookups by port number doesn't work on s390x/ppc64 arches- Resolves: rhbz#825028 - Service lookups by port number doesn't work on s390x/ppc64 arches- Resolves: rhbz#824616 - sssd_nss crashes when configured with use_fully_qualified_names = true- Resolves: rhbz#824062 - sssd_be crashed with SIGSEGV in _tevent_schedule_immediate()- Resolves: rhbz#822236 - SSSD netgroups do not honor entry_cache_nowait_percentage- Resolves: rhbz#820759 - AVC denial seen on sssd upgrade during ipa-client upgrade - Resolves: rhbz#821044 - sss_groupadd no longer detects duplicate GID numbers- Resolves: rhbz#818642 - Auth fails for user with non-default attribute names - Resolves: rhbz#819063 - sssd fails to provide partial data till paged search returns "Size Limit Exceeded" - Resolves: rhbz#820585 - Group enumeration fails in proxy provider- Resolves: rhbz#816616 - group members are now lowercased in case insensitive domains- Resolves: rhbz#805431 - NFS files/folders are mapped to nobody user if NFS top level directory is chowned by a SSSD user- Resolves: rhbz#805924 - SSSD should attempt to get the RootDSE after binding - Resolves: rhbz#814237 - sdap_check_aliases must not error when detects the same user - Resolves: rhbz#812281 - autofs client: map name length used as key length - Related: rhbz#784870 - SSSD fails during autodetection of search bases for new LDAP features - Related: rhbz#814269 - sssd-1.5.1-66.el6_2.3.x86_64 freezes- Fix typo in patch for SSH umask - Related: rhbz#808107 - Coverity revealed memory management defects- Resolves: rhbz#808458 - Authconfig crashes when sets krb realm - Resolves: rhbz#808597 - sssd_nss crashes on request when no back end is running - Resolves: rhbz#808107 - Coverity revealed memory management defects- Related: rhbz#805452 - Unable to lookup user, group, netgroup aliases with case_sensitive=false- Resolves: rhbz#804057 - Initial service lookups having name with uppercase alphabets doesn't work - Resolves: rhbz#804065 - Service lookup using case-sensitive protocol names doesn't work when case_sensitive=false - Resolves: rhbz#805281 - sssd: Uses the wrong key when there a multiple realms in a single keytab - Resolves: rhbz#805452 - Unable to lookup user, group, netgroup aliases with case_sensitive=false - Resolves: rhbz#805918 - Wrong resolv_status might cause crash when name resolution times out - Resolves: rhbz#805431 - NFS files/folders are mapped to nobody user if NFS top level directory is chowned by a SSSD user- Related: rhbz#802207 - getent netgroup hangs when "use_fully_qualified_names = TRUE" in sssd - Resolves: rhbz#801719 - "Error looking up public keys" while ssh to replica using IP address - Resolves: rhbz#803659 - Service lookup shows case sensitive names twice with case_sensitive=false - Resolves: rhbz#803842 - Unable to bind to LDAP server when minssf set - Resolves: rhbz#805034 - accessing an undefined variable might cause crash - Resolves: rhbz#805108 - sss_ssh_knownhostproxy infinite loop hangs SSH login- Update translations - Resolves: rhbz#802372 - Pick up latest translation files for SSSD - Resolves: rhbz#802207 - getent netgroup hangs when "use_fully_qualified_names = TRUE" in sssd - Related: rhbz#801451 - Logging in with ssh pub key should consult authentication authority policies- Resolves: rhbz#801407 - sssd_nss gets hung processing identical search requests - Resolves: rhbz#801451 - Logging in with ssh pub key should consult authentication authority policies - Resolves: rhbz#795562 - Infinite loop checking Kerberos credentials - Resolves: rhbz#798317 - sssd crashes when ipa_hbac_support_srchost is set to true - Resolves: rhbz#799039 - --debug option for sss_debuglevel doesn't work - Resolves: rhbz#799915 - Unable to lookup netgroups with case_sensitive=false - Resolves: rhbz#799929 - Raise limits for max num of files sssd_nss/sssd_pam can use - Resolves: rhbz#799971 - sssd_be crashes on shutdown - Resolves: rhbz#801533 - sssd_be crashes when resolving non-trivial nested group structure - Resolves: rhbz#801368 - Group lookups doesn't return members with proxy provider configured - Resolves: rhbz#801377 - getent returns non-existing netgroup name, when sssd is configured as proxy provider- Do not auto-upgrade debug levels - Tool still available for manual use - Reverts: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade - Resolves: rhbz#798881 - Install-time warnings - Resolves: rhbz#798774 - IPA provider should assume that ipa_domain is also the dns_discovery_domain - Resolves: rhbz#798655 - Password logins failing due to a process with high UID- Fix explicit requires to use openldap instead of openldap-libs - Related: rhbz#797282 - sssd-1.5.1-66.el6.x86_64 needs openldap >= openldap-2.4.23-20.el6.x86_64- Fix multilib-clean issue due to upgrade script - Remove old copy from the spec file - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Fix typo in the patch - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Use a patch and install the script to python_sitelib - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Resolves: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade - Resolves: rhbz#785871 - wrong build dependency on nscd - Resolves: rhbz#785873 - IPA host search base cannot be set - Resolves: rhbz#791208 - Entries lacking a POSIX username value break group lookups - Resolves: rhbz#796307 - Simple Paged Search control needs to be used more sparingly - Resolves: rhbz#797282 - sssd-1.5.1-66.el6.x86_64 needs openldap >= openldap-2.4.23-20.el6.x86_64 - Resolves: rhbz#787035 - ipa - sssd slow response with thousands of user entries - Resolves: rhbz#742509 - [RFE] Add SSSD Tool to purge cache - Resolves: rhbz#772297 - Fails to update if all nisNetgroupTriple or memberNisNetgroup entries are deleted from a netgroup - Resolves: rhbz#783138 - Backend occasionally goes offline under heavy load - Resolves: rhbz#797975 - sssd_be: The requested target is not configured is logged at each login - Resolves: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3- Resolves: rhbz#761570 - [RFE] support looking up autofs maps via SSSD - Resolves: rhbz#788979 - sssd crashes during initgroups against a user belonging to nested rfc2307bis group- Handle filtering python Provides in a safer way - Related: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3- Related: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3 - Resolves: rhbz#786553 - sssd on ppc64 doesn't pull cyrus-sasl-gssapi.ppc as a dependancy - Resolves: rhbz#785909 - --debug-timestamps=1 is not passed to providers - Resolves: rhbz#785908 - ldap_*_search_base doesn't fully limit the group and netgroup search base correctly - Resolves: rhbz#785907 - [RFE] Add support to request canonicalization on krb AS requests - Resolves: rhbz#785905 - [RFE] DEBUG timestamps should offer higher precision - Resolves: rhbz#785904 - [RFE] SSSD should have --version option - Resolves: rhbz#785902 - Errors with empty loginShell and proxy provider - Resolves: rhbz#785898 - Enable midway cache refresh by default - Resolves: rhbz#785888 - sssd returns empty netgroup at a second request for a non-existing netgroup - Resolves: rhbz#785884 - Honour TTL when resolving host names - Resolves: rhbz#785883 - check DNS records before updates - Resolves: rhbz#785881 - List the keytab to pick the princiapl to use instead of guessing - Resolves: rhbz#785880 - debug_level in sssd.conf overrides command-line - Resolves: rhbz#785879 - sss_obfuscate/python config parser modifies config file too much - Resolves: rhbz#785877 - on reconnect we need to detect that a ipa/ds server has been reinitialized - Resolves: rhbz#785741 - sssd.api.conf and sssd.api.d should not be in /etc - Resolves: rhbz#773660 - Kerberos errors should go to syslog - Resolves: rhbz#772163 - Iterator loop reuse cases a tight loop in the native IPA netgroups code - Resolves: rhbz#771706 - sssd_be crashes during auth when there exists UTF source host group in an hbacrule - Resolves: rhbz#771702 - sssd_pam crashes during change password operation against a IPA server - Resolves: rhbz#771361 - case_sensitive function not working as intended for ldap - Resolves: rhbz#768935 - Crash when applying settings - Resolves: rhbz#766941 - The full dyndns update message should be logged into debug logs - Resolves: rhbz#766930 - [RFE] Add a new option to override home directory value - Resolves: rhbz#766913 - [RFE] Add option to select validate and FAST keytab principal name - Resolves: rhbz#766907 - Use [...] for IPv6 addresses in kdc info files - Resolves: rhbz#766904 - [RFE] Create a command line tool to change the debug levels on the fly - Resolves: rhbz#766876 - [RFE] Make HBAC srchost processing optional - Resolves: rhbz#766141 - [RFE] SSSD should support FreeIPA's internal netgroup representation - Resolves: rhbz#761582 - [RFE] Add ldap_sasl_minssf option - Resolves: rhbz#759186 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#755506 - [RFE] Add host-based (pam_host_attr) access control - Resolves: rhbz#753876 - [RFE] Add support for the services map - Resolves: rhbz#746181 - "getgrgid call returned more than one result" after group name change in MSAD - Resolves: rhbz#744197 - [RFE] close LDAP connection to the server when idle for some (configurable) time - Resolves: rhbz#742510 - [RFE] Separate Cache Timeouts for SSSD - Related: rhbz#742509 - [RFE] Add SSSD Tool to purge cache - Resolves: rhbz#742052 - id -G group resolution takes extremely long - Resolves: rhbz#739312 - [RFE] sssd does not set shadowLastChange - Resolves: rhbz#736150 - [RFE] SSSD should support multiple search bases - Resolves: rhbz#735827 - [RFE] Ability to set a domain as case sensitive or insensitive - Resolves: rhbz#735405 - [RFE] Option to disable warnings for unknown users - Resolves: rhbz#728212 - [RFE] sssd does not handle when paging control disabled for openldap - Resolves: rhbz#726467 - SSSD takes 30+ seconds to login - Resolves: rhbz#721289 - Process /usr/libexec/sssd/sssd_be was killed by signal 11 during auth when password for the user is not set- Resolves: rhbz#773655 - Race-condition bug in LDAP auth provider- Resolves: rhbz#753842 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758157 - LDAP failover not working if server refuses connections- Related: rhbz#750359 - Major cached entry performance regression- Resolves: rhbz#750359 - Major cached entry performance regression- Resolves: rhbz#749822 - SSSD may go into infinite loop during RFC2307bis initgroups when groups appear in multiple nesting levels- Resolves: rhbz#749256 - SELinux errors with SSSD Downgrade- Resolves: rhbz#748924 - RHEL6.1/sssd_pam segmentation fault- Resolves: rhbz#748412 - Memory leaks during the initgroups() operation- Related: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#742288 - RFC2307bis initgroups calls are slow - Resolves: rhbz#746654 - SSSD backend gets killed on slow systems - Related: rhbz#743925 - HBAC processing is very slow when dealing with FreeIPA deployments with large numbers of hosts Fixes a crash introduced by the earlier patch. - Related: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names Fixes for internationalization- Related: rhbz#742278 - Rework the example config- Resolves: rhbz#743925 - HBAC processing is very slow when dealing with FreeIPA deployments with large numbers of hosts - Resolves: rhbz#745966 - sssd_pam segfaults on sssd restart - Related: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#742278 - Rework the example config - Resolves: rhbz#746037 - Only access sssd_nss internal hash table if it was initialized - Resolves: rhbz#742526 - SSSD's man pages are missing information - Resolves: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#738621 - Lookup fails for non-primary usernames with multi-valued uid - Resolves: rhbz#738629 - Group lookups doesn't return it's member for sometime when the member has multi-valued uid - Resolves: rhbz#742295 - Use an explicit base 10 when converting uidNumber to integer - Resolves: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names- Resolves: rhbz#741751 - HBAC rule evaluation does not properly handle host groups - Resolves: rhbz#740501 - SSSD not functional after "self" reboot - Resolves: rhbz#742539 - HBAC: Hostname comparisons should be case-insensitive- Resolves: rhbz#728343 - SSSD taking 5 minutes to log in - Resolves: rhbz#739850 - Coverity defects newly introduced in rhel 6.2- Resolves: rhbz#737157 - "System error" appears in log during change password operation of a user in openldap server with ppolicy enabled - Resolves: rhbz#737172 - "Unknown (private extension) error(21853), (null)" messages are logged during change password operation of a user in openldap server with ppolicy enabled- Resolves: rhbz#736314 - sssd crashes during auth while there exists multiple external hosts along with managed host - Resolves: rhbz#732974 - [RFE] Have SSSD cache properly with krb5_validate = True and SElinux enabled- Resolves: rhbz#732010 - LDAP+GSSAPI needs explicit Kerberos realm - Resolves: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names - Resolves: rhbz#733409 - Improve password policy error message - Resolves: rhbz#733663 - Authentication fails when there exists an empty hbacsvcgroup - Resolves: rhbz#732935 - Add LDAP provider option to set LDAP_OPT_X_SASL_NOCANON - Resolves: rhbz#734101 - sssd blocks login of ipa-users- Related: rhbz#728353 - Resolve RPMDiff errors in SSSD- Resolves: rhbz#728961 - Provide a mechanism for vetoing the use of certain shells- Related: rhbz#728267 - When non-posix groups are skipped, initgroups returns random GID- Related: rhbz#726466 - HBAC rule evaluation does not support extended UTF-8 languages - Related: rhbz#718250 - Remove DENY rules from the HBAC access provider - Fixes an issue on big endian platforms- Resolves: rhbz#700828 - Process /usr/libexec/sssd/sssd_be was killed by signal 11 (SIGSEGV) when ldap_uri is misconfigured - Resolves: rhbz#726438 - sssd doesn't honor ldap supportedControls - Resolves: rhbz#726466 - HBAC rule evaluation does not support extended UTF-8 languages - Resolves: rhbz#718250 - Remove DENY rules from the HBAC access provider - Resolves: rhbz#728267 - When non-posix groups are skipped, initgroups returns random GID - Resolves: rhbz#726475 - sssd_pam leaks file descriptors - Resolves: rhbz#725868 - Explicitly ignore groups with gidNumber = 0- Related: rhbz#721052 - sssd does not handle kerberos server IP change - Use ares_search instead of ares_query to honor - search entries in /etc/resolv.conf- Resolves: rhbz#711416 - During the change password operation the ccache is - not replaced by a new one if the old one isn't - active anymore - Resolves: rhbz#715609 - Certificate validation fails with message - "Connection error: TLS: hostname does not match CN - in peer certificate" - Resolves: rhbz#719089 - IPA dynamic DNS update mangles AAAA records - Resolves: rhbz#721052 - sssd does not handle kerberos server IP change - Honor TTL values when resolving hostnames- Resolves: rhbz#713961 - libsss_ldap segfault at login against OpenLDAP - Resolves: rhbz#713438 - sssd shuts down if inotify crashes- Resolves: rhbz#709081 - sssd.$arch should require sssd-client.$arch- Resolves: rhbz#709342 - Typo in negative cache notification for initgroups() - Resolves: rhbz#708009 - "renew_all_tgts" and "renew_handlers" messages are - being logged multiple times when the provider comes - back online - Resolves: rhbz#707997 - The IPA provider does not work with IPv6 - Resolves: rhbz#677327 - [RFE] Support overriding attribute value - Resolves: rhbz#692090 - SSSD is not populating nested groups in - Active Directory- Resolves: rhbz#707627 - Include valid "ldap_uri" formats in sssd-ldap man - page- Resolves: rhbz#707513 - Unable to authenticate users when username - contains "\0"- Resolves: rhbz#698723 - kpasswd fails when using sssd and - kadmin server != kdc server- Resolves: rhbz#707282 - latest sssd fails if ldap_default_authtok_type is - not mentioned - Resolves: rhbz#692404 - rfc2307bis groups are being enumerated even when the - gidNumber is out of the range of min_id,max_id. - Resolves: rhbz#699530 - Users with a local group as their primary GID are - denied access by the simple access provider - Resolves: rhbz#700172 - RFE: SSSD should support paged LDAP lookups - Resolves: rhbz#705434 - IPA provider fails initgroups() if user is not a - member of any group - Resolves: rhbz#703624 - SSSD's async resolver only tries the first - nameserver in /etc/resolv.conf- Resolves: rhbz#701700 - sssd client libraries use select() but should use - poll() instead- Related: rhbz#693818 - Automatic TGT renewal overwrites cached password - Fix segfault in TGT renewal- Related: rhbz#693818 - Automatic TGT renewal overwrites cached password - Fix typo causing build breakage- Resolves: rhbz#693818 - Automatic TGT renewal overwrites cached password- Resolves: rhbz#696972 - Filters not honoured against fully-qualified users- Resolves: rhbz#694146 - SSSD consumes GBs of RAM, possible memory leak- Related: rhbz#691678 - SSSD needs to fall back to 'cn' for GECOS - information- Related: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#694444 - Unable to resolve SRV record when called with - _srv_, in ldap_uri - Related: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#692472 - Process /usr/libexec/sssd/sssd_be was killed by - signal 11 (SIGSEGV) - Fix is to not attempt to resolve nameless servers- Resolves: rhbz#691678 - SSSD needs to fall back to 'cn' for GECOS - information- Resolves: rhbz#690866 - Groups with a zero-length memberuid attribute can - cause SSSD to stop caching and responding to - requests- Resolves: rhbz#690131 - Traceback messages seen while interrupting - sss_obfuscate using ctrl+d - Resolves: rhbz#690421 - [abrt] sssd-1.2.1-28.el6_0.4: _talloc_free: Process - /usr/libexec/sssd/sssd_be was killed by signal 11 - (SIGSEGV)- Related: rhbz#683885 - SSSD should skip over groups with multiple names- Resolves: rhbz#683158 - SSSD breaks on RDNs with a comma in them - Resolves: rhbz#689886 - group memberships are not populated correctly during - IPA provider initgroups - Resolves: rhbz#683885 - SSSD should skip over groups with multiple names- Resolves: rhbz#683860 - Skip users and groups that have incomplete contents - Resolves: rhbz#688491 - authconfig fails when access_provider is set as krb5 - in sssd.conf- Resolves: rhbz#683255 - sudo/ldap lookup via sssd gets stuck for 5min - waiting on netgroup - Resolves: rhbz#683431 - sssd consumes 100% CPU - Related: rhbz#680440 - sssd does not handle kerberos server IP change- Related: rhbz#680440 - sssd does not handle kerberos server IP change - SSSD was staying with the old server if it was still online- Resolves: rhbz#682850 - IPA provider should use realm instead of ipa_domain - for base DN- Resolves: rhbz#682340 - sssd-be segmentation fault - ipa-client on - ipa-server - Resolves: rhbz#680440 - sssd does not handle kerberos server IP change - Resolves: rhbz#680442 - Dynamic DNS update fails if multiple servers are - given in ipa_server config option - Resolves: rhbz#680932 - Do not delete sysdb memberOf if there is no memberOf - attribute on the server - Resolves: rhbz#682807 - sssd_nss core dumps with certain lookups- Related: rhbz#678614 - SSSD needs to look at IPA's compat tree for netgroups - Related: rhbz#679082 - SSSD IPA provider should honor the krb5_realm option- Resolves: rhbz#679082 - SSSD IPA provider should honor the krb5_realm option - Resolves: rhbz#677318 - Does not read renewable ccache at startup- Resolves: rhbz#678593 - User information not updated on login for secondary - domains - Resolves: rhbz#678777 - IPA provider does not update removed group - memberships on initgroups- Resolves: rhbz#677588 - sssd crashes at the next tgt renewals it tries - Resolves: rhbz#678410 - name service caches names, so id command shows - recently deleted users - Resolves: rhbz#678614 - SSSD needs to look at IPA's compat tree for - netgroups- Resolves: rhbz#670511 - SSSD and sftp-only jailed users with pubkey login - Resolves: rhbz#675284 - "no matching rule" message logged on all successful - requests - Resolves: rhbz#676911 - SSSD attempts to use START_TLS over LDAPS for - authentication- Resolves: rhbz#674164 - sss_obfuscate fails if there's no domain named - "default" - Resolves: rhbz#674515 - -p option always uses empty string to obfuscate - password - Resolves: rhbz#674141 - Traceback call messages displayed while - "sss_obfuscate" command is executed as a non-root - user- Resolves: rhbz#674172 - Group members are not sanitized in nested group - processing - Put translated tool manpages into the sssd-tools subpackage- Related: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - Also add the updated ding-libs to the BuildRequires- Related: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - Explicitly require updated ding-libs- Resolves: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options - Assorted bugfixes- Add noverify to sssd.conf - Resolves: rhbz#627165 - TPS VerifyTest failure- Related: rhbz#644072 - Rebase SSSD to 1.5 - New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Resolves: rhbz#660592 - SSSD shutdown sometimes hangs - Resolves: rhbz#660585 - getent passwd ' returns nothing if its - uidNumber gt 2147483647- Resolves: rhbz#659401 - SSSD shutdown sometimes hangs- Resolves: rhbz#645449 - 'getent passwd ' returns nothing if its - uidNumber gt 2147483647- Resolves: rhbz#658374 - sssd stops on upgrade- Resolves: rhbz#658158 - sssd stops on upgrade- Resolves: rhbz#649312 - SSSD will sometimes lose groups from the cache- Resolves: rhbz#649286 - SSSD will sometimes lose groups from the cache- Resolves: rhbz#637070 - the krb5 locator plugin isn't packaged for multilib - Resolves: rhbz#642412 - SSSD initgroups does not behave as expected- Resolves: rhbz#633406 - the krb5 locator plugin isn't packaged for multilib - Resolves: rhbz#633487 - SSSD initgroups does not behave as expected- Resolves: rhbz#633406 - the krb5 locator plugin isn't packaged for multilib- Resolves: rhbz#629949 - sssd stops on upgrade- Resolves: rhbz#625122 - GNOME Lock Screen unocks without a password- Resolves: rhbz#621307 - Password changes are broken on LDAP- Resolves: rhbz#617623 - SSSD suffers from serious performance issues on - initgroups calls- Resolves: rhbz#607233 - SSSD users cannot log in through GDM - - Real issue was that long-running services - - do not reconnect if sssd is restarted- Resolves: rhbz#591715 - sssd should emit warnings if there are problems with - /etc/krb5.keytab file- Resolves: rhbz#606836 - libcollection needs an soname bump before RHEL 6 - final - Resolves: rhbz#608661 - SASL with OpenLDAP server fails - Resolves: rhbz#608688 - SSSD doesn't properly request RootDSE attributes- New upstream bugfix release 1.2.1 - Resolves: rhbz#601770 - SSSD in RHEL 6.0 should ship with zero open Coverity - bugs. - Resolves: rhbz#603041 - Remove unnecessary option krb5_changepw_principal - Resolves: rhbz#604704 - authconfig should provide error with no trace back - if disabling sssd when sssd is not enabled - Resolves: rhbz#591873 - Connecting to the network after an offline kerberos - auth logs continuous error messages to sssd_ldap.log - Resolves: rhbz#596295 - Authentication fails for user from the second domain - when the same user name is filtered out from the - first domain - Related: rhbz#598559 - Update translation files for SSSD before RHEL 6 - final- Resolves: rhbz#593696 - Empty list of simple_allow_users causes sssd service - to fail while restart - Resolves: rhbz#600352 - Wrapping the value for "ldap_access_filter" in - parentheses causes ldap_search_ext to fail - Resolves: rhbz#600468 - Segfault in krb5_child - Related: rhbz#601770 - SSSD in RHEL 6.0 should ship with zero open Coverity - bugs.- Resolves: rhbz#598670 - Ccache file of a user is removed too early - Resolves: rhbz#599057 - Incomplete comparison of a service name in - IPA access provider - Resolves: rhbz#598496 - Failure with IPA access provider - Resolves: rhbz#599027 - Makefile typo causes SSSD not to use the - kernel keyring- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP - Resolves: rhbz#584001 - Rebase sssd to 1.2 - Resolves: rhbz#584017 - Unconfiguring sssd leaves KDC locator file - Resolves: rhbz#587384 - authconfig fails if krb5_kpasswd in sssd.conf - Resolves: rhbz#587743 - Need to replicate pam_ldap's pam_filter in sssd.conf - Resolves: rhbz#590134 - sssd: auth_provider = proxy regression - Resolves: rhbz#591131 - Kerberos provider needs to rewrite kdcinfo file when - going online - Resolves: rhbz#591136 - Change SSSD ipa BE to handle new structure of the - HBAC rule- Improve DEBUG logs for STARTTLS failures- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcacacacacacacacacacacacsdedededededededededededeesesesesesesesesesesesfrfrfrfrfrfrfrfrfrfrfrfrjajajajajajajajajajajanlptptukukukukukukukukukukukukuk1.13.3-60.el61.13.3-60.el6 sss_debuglevelsss_groupaddsss_groupdelsss_groupmodsss_groupshowsss_obfuscatesss_overridesss_seedsss_useraddsss_userdelsss_usermodsssd-tools-1.13.3COPYINGsss_rpcidmapd.5.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_groupdel.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_override.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_groupmod.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_rpcidmapd.5.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gz/usr/sbin//usr/share/doc//usr/share/doc/sssd-tools-1.13.3//usr/share/man/ca/man5//usr/share/man/ca/man8//usr/share/man/cs/man8//usr/share/man/de/man1//usr/share/man/de/man8//usr/share/man/es/man1//usr/share/man/es/man8//usr/share/man/fr/man1//usr/share/man/fr/man8//usr/share/man/ja/man1//usr/share/man/ja/man8//usr/share/man/man8//usr/share/man/nl/man8//usr/share/man/pt/man8//usr/share/man/uk/man1//usr/share/man/uk/man5//usr/share/man/uk/man8/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector --param=ssp-buffer-size=4 -m32 -march=i686 -mtune=atom -fasynchronous-unwind-tablesdrpmxz2i686-redhat-linux-gnu?7zXZ !PH6G]"k%}:w{!vQ_99e[7h  YCu.ぃ|KЍ}fYxV EWyA i[c,~QB^a-`xQ9~WmU4A;¾(&qU~RRZ6iI>S>q'8ɢ'ω*D59L0UB`{ЮD ݮ Cf^HEfoBL1;oEEF2CLϬ]ۢ@ͼ0tNonz9Rݬ-3x`T?"O9;Y͠^]/?2nW$E[92%9E~B[@cvn=,NKOa\]BSP)Ksߍ5_Cm +;m&Q̶Lbx5 CÈ׽d{b|ܬȾ>ʫAw~MosOmze-Lk\_dÞ{}?vʼ=ݜu/NE!!CQa?bW{?HIyܫrVmYH_sf)nS+ %{0m]ԢɕwF m$iP?xggeT궓=||h2߱_sE"Hwʽ B? DMf(o5){B7V 7RLHڸۅv A!כ0)`\>~4>u0}]j_UGR?;!!}HWZr7s?C`~NNH*_LAM3QԼċUL1Ϸ͢arLiֻ  5ٍk(maA< A<.o42L fa:y 608Q,) LM:?V̩u% C⧂~u[ ] q%W[AKjUTn[3>c i{^fs;:֔{PB]1:M# qhB ZUP `^Y/8QaIfBMMR|=[dxY`9ah-K Ksk߮ !JK|6 WQUkr1%o\%'D[>f&\cp|&fΊ@ /6_K14Ƅ݈hRW(^h J?>^M\>FFnAT=RFA,[s3'v]-Dy2h8d_E%4;j:zk&t"ʉ VG*ĺ^ԅR~ڢUVQ+_X]k~D--1dB0=km)Gwӈb+FB@eBu$l|6<_q1I&%Ia0:!έtGeI`5k=xHazDC!YTL5E^:QVf-oֻ"䃸Zf{rBaEeRSbr泼<{%r*))KZLAEJy`!Qrk܉B|uOcw Y'w[Z+PPZ'A)8 ]/N/5hP8Nɫۛ;VlBqGrjM8w.!dv r!3f0ͪԦ| H<& f|P-iͲ^ ,葮?Hp>pzD{jZ20}+I1'$eZFk7teh9:H Pl@~@9D@aBAyI'2mƧ:9#Ԏ?0D*4&C՛|24G֨( jwbհtm!Id:-= ,$ٰz$[GpgngC+|m2jC"P+e0"a(5H~%TH?Ѽr[8 ȡ&^V\7D Xp ,5,U:Z̈T^@|df̤M.S`o BLnbM\͸IJD S_Ҫ=~ip:OsoP4Wz-zGTӥ1{BzgG TkEly\ ) IY"<pKf/uT&azxY{_Q(^/zW?v#}>ܥAc#`'z x,\*ٟG(Ƕ!>l p6 m$=nmfef(fJ~! aYHD%Fi[g&T&['|"Q'Z9 _eqvZ7kLR|Ǧ`uJQGۈgy6i<Id&wgLM#YۥdOp"\V}H}w|E'-JȮTD認?;w\! 㯍5n5H֞٨-seIZ/N`TLBk^Sert.^"3}G3jS_ 5uD%:F9KfRSD?{UuWa&}F{"D>2^R -sba:=~/WSaQ\Y5!ÒJiFkA;8Vf ^DZi͍ ]*&}j '$|![g҂!mvtt!Ti&]Yf!9\uS?(c_ިEm˕ uuz"Lj_.mE狼VURQd{O.l{^NAd+хӎLIJS`6yBT@?}PFH*p#GX/Gy~tpIAѣ'٫9d:5I/I+ϲpOf1H!k囓Q#Aٜ 5e}qQifՃEͻQ\zj` {};Ӹ"OP6-4)ˇ2!pM[д9+r!߀l3yßbwwV=an!1gO~%2=eWvd|#㏄~فKBhY}2໰ V3fZLJOPE7 Oo.<[_ΆQ-ž2}g=Q~Fs)jw/2M:RNG~A5NB0< :p^x1AݚWo`u;Q!"|;O6Ǡo%EM SLh3K?9=,Vp=F72[U=X_7-2{AVoUK"׷dᤂ:-]^@aϔ?E4@yx*3>ƮC$_fbA(-J"WbiH A\e㻓 T5K}iuG0IS'YG{(l{H1  |kQhpRo~#1=\ y}5D MQ@TjD̨QFgEkXd Ha(X* U n *^$GA_0Z?>TU^pg*"0փid&oUb҄A~ -c3$EZ!'*L=WǕD^.m'EsMW@egc5}E-1TbGXZMv0X\b! Ep5s}S]U1~Џ@%MVW^QD_231_3a}N /VGX$ҙxrg?D?n :Gl + r|<+3B}O=z/H5"L)>HPG/9Prv2g-*Wy  vnISiȄ7{V)+ybd;`k(E>ԥּ8>4R_ޔծu?MhOJ$'V9:0 آ0]/ ʨǷ9G{m>0u{ښJä48c`w#P] 5CE-Ͷ', b[nmq\.=I2(9TGgFfG ¶d#|i&N>Ү z诹FJcz'7Ѯ(*.')en8=T643_фⱦCSl> sRXX-z%9~2L)f5, @N5<&a!/~Zv3UثՓz2G_w8瘀䟎 ݪR}(>ll̊~J/qW n&bNGKdEcęPS*Ve6Cї3%i&qspwk,GOC~*gUOCbBcWyW9/UCXRi* ʟcGSIWEm LM禈n%1#ۃ‰GZ) Vx 0vB:7ʛhy愫j@6 @P iڄkNjO`k imؚ ?n y-鳘e5No<|xx˩ӭ6j0 fr ɳ bLD}v0_7J"$oEFTH~#)6:a[ڦҟ^_h{[DWU_fp l,Cgzӏdqy0^w 5>~^rdkFY,@dmc_a ]h$\XZv@/arrq*r|CYUH}%_w4L"⽍y8pPӾ"ɸ4U>^-GѝUDwdHcHp(ϕ@h:Ѝ}A7kJj}㗘)։`V}\?v/3+hl]9T1Ppxpߒeiyͮ(B5`m2NjE^.UW1>d䠉0W)F &̆;Xk1VJ6 q^/gE.0#}2Y>3P}0TNOQxnL fr_ azoH'2*l^18PiTbR=Q>V8)0gPQTZҽ.,l"c&vʓzf-;ͨM#/ %cj4}q [chӫCnwHrH״N?n>B/BFb ͚@Թx1'WZ5{ўQκhdgn#KRLS@[kiEQWU&A*C`z}hP33xYnjӠ{3eaa}5?aDvnal<7dT+a.F4G y~VQ-$.'6,C +! ,X 3IJ"a|-xkIʍ4 ԥU*woo jByӛzv|lmmBp(iQ }?NmW`Ej\# /{\%հDF=`;gSg{,izlq3*&`CRLh'Kt=߃ML{4W,IGζts c:b'rKe14QT'~н> R1ܟo$P ?YN[ZŻ,he FIx![[O%BKkjxXc8dǟq@$FSK"ҥp9J-Qʩ0E13ݐF'J3PnA$hS}3E= 7r_ӞE?rGK/MAˣ=IAF2JIqyN2bq*ZE=\"^B!BA`]JclZF(yn]IWG! -EfX5`x,U;> ib8.q[Ya Qy _Â""q@:Ge!aC8 ev+ |U6UjtDЩO/F~ڒ:[,{t? 1s %qBag*l+-;$PISW}qOp,d?h|\&;3[W[^sa5981ɐK茎ӫΙƌz6"=t;8ZX)!ީe4}~W =ASZt6:T:#?Tr$~cS|668dpd']ђ/+:_܊;9b7f#`ֈцn$> BTT츾f WŻGtn i{.6T7P[T}sc`vo**ٜdP5\\LZ,q<t1x=p%;,;S݈\8Os2qj`D{‘;hݭ "m{%*7E"p3+3$o{IjQ|8,r{%$oq-_&{?,WjNE ժg`1nϨήd40k 6@GCWs"O.9*`|VR|mn8=[w[ӱOHCc}-u@w))bcfERe2"rq21/93Gl_1m;I-T(%,˃m5bH{Su0Y_y 1av]ֵ1@Ewz+^K9LI hh?!'hv GT)AOj(5|')yA;&S!&Hi"7ދz9+^siOjVI{m*bס!9K`(8^ }xib@^aOxQo@GEEM4Т!KEiCK1ЦonBx~{uXvx8һ VLzq=`Qޒm!=6tP7/Eі~z LTuw ߷wں.'8##(`>K>o[訉_O6UQҵ(FXᶯh:̬F@AKFmLx5K t]ͶH3wVV\sr`@W ƷS'[Jʮ5y׬rzmXN}X.lJ`V|YǩeFӧB|LAL囉#^]gHc[)kz\wR ]3-|$AGVCuev'^Kr͆V.OB 'gTF'9Dcwx =!% [ՏGRɫLujKJ;*Q)',(&I͔~M̶{D 5u+7KћEA*%6,rdMWouLȳf7='Ț"~ uT5'o`xgfnAW}~IaM4S`D:bf'[:ϙO?ÕKEҟv"|j RaʛTS^:dfߘ 5l&yux Lwa俭ktE6qfMfz <3t}h³h#+(J(L! afN¶ bG%v?iYޥT9T0 ӲCaa0$BU˕[iOb؟OX*vNSR4< X'%מGO!!d'r<Ɉ0y$. nCTTaZt78ήn@EPff!Cf~_!hK@ g/SxpE*Rҍ YYR(y,$KW SREvʩcI 'pyX>dڤ 7#06ε=?J'CEsNT=)w}I^͂ԷOﶲ7Ygkv˨NudqZ#M)U^ȲQ൹"v5Nam@u "(.eW9Ys'Ȱu(q`qeT}u:Mx]W**/ գAAlVe }#{ϸh<&g_nr] w:rk//Y{A~ ?D|ՙQk'}f?]8iRM*̗:LJb,L0+ Hψp'A6o5HC5O}h/F&%Uay̮*n$&}`iM?L(u. >0cƀiWtZW}kIXz+(nZԗ8(6)Wظ4e?j7>B29>T2쌰7<3g^UA ^9q{ h5.r|E?W؏% CTXa\ziO#9;{[e2&LT:Y!~t_Ѝ I.Y֝ @ΰr@T34YU#Eu(Udv"Z2DnOR}(IR ~Cbi|@/UG_@jNFvIdQ&w0CU^GK#`DBzu6qk|0KX::|h͉F~Jfdf%gL+W阂H,#9E/& 9sh=:y =GНf; CXA9M "=ZKHQ 2W$zbQ &}yV0|l+D@jCUQ! ҫf􄅎DSP.nIt MlE超:p5KuM˕8Tk&nq ZifpK+(-c*}=q_ESdyз$eo"L~Х qJt'}t=0xUR }$Wc (%Ҕt;)VOfgܻNh~j;$y[g-=iʓ^l3YY x_uHyUWKTzZ#NtPs󋦱߃}})7[axfnRVؐA` Mfu6ZQYm{e6k+R୮6ߢp/2S>'j< (2afz/I 5ڋ ``6_0) STiL;8cb]8dz pS@PͰuH/*dH|Ʒz!y= }:Baurv68vFծ&  EPHjC=~b2" p( 61^O%h%N 4Ep(e_h0orP[-wh7XՋ\aTT&dZg#CPdF۷EڋZZ YѪ5'1b=O K9"RThbf7|gn`8+FMfQjVs A25vfĽǛnө4kDB$/L.|˜UF@Xv.tIP_-Eqm=ۉbMYV (`a4;kP!y}3*gEEvר=.Yk"!ԻO{VZbr6Jg99ҭA9x$ W Hk!Z[S_k'#m߯'x~B =LKaN=Y8 ɮE%R:DO1q 62ͫx$@f^!Kj5T.c&vjE| #1j}@>v>v܌~vP&. ҿy^P&Q y\ Gq|u#A֜|{m!M>ku;T7HS7v˯Xʅ:% g)v@J  kHlȌ(cْCvXf9l&'3u:Gs.b9+cY%:;gUʹ05 /&YiiyKäG(:sB mti}dee2!EQn(u曆4sQK쌮9)I&hn N8 W⃮ hC33ENI.tZMJ~=3Mfn0 1-t^5\pU@ݑSꆮUyCG%~A<G#7G"l?os"ad2INn+GyXbrTcZX?E T8Nw4Dv!OQhP6m /1s`$]'p'= 3P؞`͛zA0闋NKK, n ғ%|%_@{HM!Hy_l=)/?p RPl˱ +ty{@YG&^9IĄ/Pb>" qSYZ:]hN>ey~`fة QXuMVXvr 3s{aEL*_̂e%%4plj0Ea/yi"_0<{H}6bIRݫ"Q?=@blAyx3BoQ 0BHjlCk%k掿Qu{ߨ5ΝcvFS\GcwuT֪.yK8#5}Ms-"4|c[&TwB `]yDPU4l1XX"|֨Ƌe??}# 10Do,7$KU_пScO36՚G6‘~r*O5$ 2F\87yI΋UDY)n L#L@XLucTIilwS3g8p02I_-9ς*b:}/ԕzK_;GpEY&6R͸Z~6h%A&]vyOa\>Ɂ~C-##}r;6gtH:u܁ƿ`9D6er^Q$PkP8b_}c=D Uw̔$Q)#% %y^ՁϓS}g;fM}t̤eZkxOg Q] GL$@~VtaY>ȼQneΉWx] k9o2Ɂ{.2 VEucag= "l~x4Bp#faջ(BhxRb"z EI]A# O="V$V )ʚ |]ut[dj>ǚNՀZ;{' Q؟#~*W(%jWϖ['oH]xҌyC_گ"N=Sk8p (獐')M ~9\͠5{t:(S  Z;!~Ug f˘y/${.:φx[Q.hu4َx>YUSuQ(⚷'ӹroh 1l6@ר6hyKȞE-}r͹u=UX#hbI%Rո譌 h!".Ɋ/#C2İ0 bfX* ̰@u]ײ|es<­q䀹rmUgaT.1߈6=p\-W^${'4hF,(?d*O.Œ,ryS e:<Yoʼ +˞:F1y65Kа1 2dhO'HRnવCP!ˁ6Km MCK=EK7њc\>N]49wmY5[=b8swY)f_g&wrJV'U?e"Ϡ:bXFoV c,Y%`IE;L 3qjfe*l@'8&,Xn+^BCJGJ/;\E~M:^!7"gZifzB2p~6ܯfZkok{…lQ홴@8)+qfq+ Xzp"2RX?@Z*pهMhsQxqk@:&Lk RVf⤁tD-aen-no \[6̐Fז B8nxsܓŧF C-si2/;i֛G"76㛎(*$d% &[nC t?s_ ?`Odx Id`|[Tm}(lhEK}_w:$oN(3eVL{ā\`^{-m F4t7aFXHf;5"m5)dʿʩ2P+!3*Kui*EŒQ8ndퟴri51=~+L3nsA=VTn%Cc^UIkB掐((Yvk~|.-ܸMӇ HN_e^ɚH^rBZ0Tws}XFPҥPǑہm)$ƛJ{6S&8O#sd5 !5J*M㿊عF!j _C}H6|}\yaOI.>PbxEq4k4]b` L9[ &v] H;!8B"?ww\ئyMFϙK%7A {d@\'l 5|cC*Ӄi&siJ@ [yǧ|V$"&kH\J^рЩBD0:+o1"#rOT'.rJ5)wd\~ M5c>2hU{I $*ΙPN /jM64*٥~b9mkI| 5yk`'wru֚)HZ5:@)4a6]SG8i{Gՙ8sdWz8wo(Xwy5/(bbKg(Z+d%_{qDև{GDŽ7en߱C׉*5ŒUFwkEqAdF6~~@(ι"G|"B2 ) [4U.\W:lܬ8i#/`Fia3HEO^.\ ly$fu+BV'HrС~ujܘniGdl9u#2 #0~RQٟQkCd.rUI;X}kZ~I ?iP\qKgɼk&9 Jݠ=641JsEBT !;{V& Son`zquVk?ߗ~ފ coXҦ ܃Z?{Hr// p *PR6uSC JQy[? `l~CUӤ$t^5Ր$9#'s[SW7uAQ2+*g*$ HH9C"Y܊L.c7EBR7D=$EhH٦EdמKd%`|24|LҗbK ׷m IB$z$,tzk&7eߊJX$H:٘LY%>磗^'mG+ }[Ķ鄲(N7@¤L<GǏ7o.sa62iJ"JۥqaxOOQRQ̩*jh ;x]9da{Eh]c ^hm^>M`Y7sKd,-d36dY/EdS/m&>CMgڃ}uLc;KP´{I#%2m?da>5wCeHq\hcrfL)]ZSi7Δv,t$$fn}&8w|;kLVtځ[%el;xԒU);P'b_AB1j#bK&$>읻Wg C\#$Q"mm1GCv]N* 7XI`O*/؂a?~f,-a1z&qlOI;1R$O4Gx F[u|y]7*ɹo~;06 Xmsq9Ű# pGTK @ZyR3h9G +}᧒ǣ6'p yG,̢}?|m[##}W&CCRϽ(FQT ׋|@Ʀ/ܱYм*Z9 `爼KVg%}$xF*OPCHt[pMBLP@Ef䝛z:LDz=L?ī6ب!uAoş-^xPUu vNNj]8^gE1 ƥ]*tf55gz2\j6eUBБm(B!S 5E^wopn Ugc=%@??$K\1 ~"ƯN(^F(/w+iz3BAA60)LA1w^5| @bRvN +&|^$Ϋ 4,\7V},[RיL!p0zQվun$'I ~\Btʰ-IixC3OۦH 5U`Ơ6v[&5nT #!rl>X:c1Q#| !Lj>>_-''Fzc3ger㢋Wpt6(!*.*MKN춾]s@`h  =p^0 OIsD{(ȸt¥Uh>q $hǵ|L#W.),%=-RH:bJ;JaF]eW{- k?b*|Y X=DV-Z FL(bSagE'z]mT}lᾑ&_N/O ZC `c#=W|(NL5 Ng_uD&patij+F,0JhH/UazjDƚoڭI; A5v\G`':XaD%1yOGC]!M[=>o :ek*+aQ$b7lMɕh82?17$֊0p*;6ɠW֦,Jvcz>#sX{PuKST;:OZvTD7Cu/˔lP6>?wW$h+Lb!KM{F#s]]d_BuYSwQ68AQ{5m⿮m2KKi 8# d4૘tt줚izھ\]Ey=",JJl.\^DB{sA#ePw%aWnM8 ǦV(Lk+1AMTٟcJni++`Z.P8^+bT޶ `dtJI҃sF|+ᒓ:UJ'<$?i\1*h2 veCz,C/( |o? '@SG{z moMX#VVul# yi.D ݁pK5tfM,A\ TX,9w \kqiT,i-Ƹ$&]eV4'gTȶ:HPwS 1,{/Eqa|^x(UG)6랲@Mکr#K|ne5躍ت.{ JWlHgEZs v"ՂHͩg_ADvs\:9|-'S,dJ hL =`v( vK ';P&etU'UжY֎ٗ&}'e+#!y\uAFp$Ukg.}PdV=cB\^mGxLرm6 ՘Pw}B(o|%Dy^iAl~wt ~q1"7y<(U*朻vtQo)Ǚj_ʹx4t&jpAbH[95pf*s0E-wFpz^df!C3.0 ^eח qڀm}Q6=ٓ#d6Q*dq)8Q 7|P>r . ,:A+ɛXkbOI QiIߡ K_4ͽ\̚OڳOV_VU`{| k <fXw6os3@cUA5"o{KfOY5w!smZ)/GHJ- TDͦ&fbV:ReypKf0s.qoVRy(r*cT 5\S`4zgSG8'15LyHCC?;?&6r0"Br1 }:~&&S'uD6{␭)T=92{*u6zItRWz%tCV oz!gQ!c/_.L^01‚<$uEdD}5]yEv6=fWf 8@@aݣ>?EvI[w!&Q1B8d8QS .§Xr4:y~aj(3*Z0F ]$Fv3H+TqDXPKS?'} ldc4>`oN r$B<8qCĮ|bļ!gӮ<"^sw2S@q|Gtofe׬skό?DtB6x xMeê܎9z@䲨hcR/ȰJAx~K޶zO-r Bb-yĩXs;=I6>YvˍvEm|g5JW9kH4s~F[DEz*jt9XMrsCiA|-:H:kD7WZa+8GS EO@GTzHqۄ5wE4d@H\'Lh,d%1xAm9*bWIX`c×jn>{۟cbWIR=,9?M1ȭ: fqC ^"=>7"p%$V3cAԳ, 9W^͜{ع,xFIʅ~.EJ<(&Xؑ"DX:ȘzFtF'K5}}㕨R (EϮU~?ӁPw,A0[C3^r8eL`B?ƟJޅtnb˝|}+)GQ2;tx50M@;Uk0~q4n˴8;"ӯƩR;n2&݇'\ērUx<8%䉕dGؐ uBIx9p3C3^J旋PXlmʄބow#Yۡ8[LyH׳B'w37u $#@cxJZa<.SQS.1A[% ,<-*/b ϡaޒ ٧kro*(~8#O.>q~ݣ(Wynss:dR>X; U2 MoM ٪{iZPC NZA'YeRya*M1H1t@X @_:+=g$..n(/z,I̬~A ӈ ah;".#x%b7ҚڦYڏt#7G-;}]tjzKe z*_M۳|0fּ/LLwO:R>@hjs!w 잜oOd9r> e@8+e/fϢyPEE\A7|7,ruɓN%Zܭ3˯G#£: yquZ Յ |;r"~mlbgh ZBJۂ;n/?a5`pC^IbzӀ@EVE kVՐ8뀉)ZS/ l&=טHNywj ծnu4 XG֕gY/m?eçP:k|g }ȳ?;)GLio@M/YreS* ߠ bބDl^'c2D\,&N%`:bB50"s(ZFѲ/tvuBJ_Ḫti R𵌉() oruT9/ ׳gFıC:wF D? _ca{YS|r^gM1^2lpڴݥB܃^myb#˴ j+$*@;tj0E?7A|"jlpp^p21mʙ)o< Ȏdno/ .t4ӱ*2qZzA&L mtOE%e]U& G^~!Νl|)Xწlb1lw2/ȯ;@¡Rki4V;ՎLI|!yU9֕'8=&b-]ުZM8$ˑ%K /ﴆQQ wC-_j!k]CoVοW {y7Yw%KN̓L[`(NJ+'1}O{ j\^Ǧٜk.S粁X 3ZQ_;|@灾GyMTxF1E{FIJ;m|N45S\mVIy<-kKHl,, N_E[-_"."V3}ՋRQϣ K.@>[9K} g+IDSF#b?tfO[` ]8>Ͷt}<~O) glǦG*gF/GBQB6=xi0W&M,pJ'Ъ__ ^\Pizm.B#b ;FO3)2UGҰ8 <&Ι;ʎdEwL!%LPna]Hx9oXLNȍ]bIkdVC\s~XZ揟ZPg րmXAv ΢?=bba(zؕ,N_Ҹ[I4rKrj%Ӄ>ߍ,L8VZ\3A;Wv80ށ;IT2B ?ڟ= L1qn/#񴙆nwxS&?,xOQQBoT`ulj'FʎO>,S-HРLэ7M Oxs g5Xt#e]Uޘ>ɩO8evR}fe@F ΨE&LyYcq&LhtԖ^ Z!_5b[|;KxW"]]#$, r-ǎoȁ$H mU-js=*-_)a0*Xvdږ޳E*XTi[v3u4Xt$文.?.{d!HpB臻>&'C:ٗCf4<V%E>T8FgR&l%W#%?eٲ Wb?_ J/'3 bL;/Zv Hu'CrC%5bXZ|%rUL `Gm#W`zѸ\&E;o ˄tn_Jb_~7E E?6,ًq"6`|u( =[l}<<4HB)=/ GM5_ u HFTQDVVJ@*.$`,֊J0sK* /WЗz'o3Ӻtm*("& hU|G%PXIM吓5eПUcD%So7Re }&RQ9&^p|Et=&_$0 N8꼭0H^3w렦̤_@LGfMמAuʉi8GE^rLڐ'ƂG,bLZe3.;)d c(V &t?MLّ~VJ\ ORz+ۢȟ^6WX犱qWiV.$ݕ1޼uִ4ρG lS#1Ȕ]5dfJ o.qI<;ǐ  "b .а0*%;樁/ʋ]>m񃞪Bo<8/,Wajv'0&qΆ0)^t\lb02` }cS&LAy[5p侶3 CeA7۷,6g(Inw/6X%RCy:؋ >-םH4JWIC;IΙ%k,ynG*ɯSs:ziF/f7R /Yn\5"_:Y?bk nz$9[ٗ/iL]:Tыh-ZS~vyYciO' _Lr َ MpJJ|yȁvOf1KyS8O~>im5٭1v6ڹq'_NY0 4\cڡz8,md"'<8Ќ>I-(&ZCUif8% r=xj;{J}Ke (/a`n;P%4{ `3M).wV]@ٯ}@Bkz8F|!0egV4'5V#4 .a4{I"zJCvE̽( -el&%?״$ʰY<\e0ѕ,vE:ijj N3wۈTٞxB 6QgMAgHD*hGG\~ / k!<ɒih,$hy^~ZِѪ#[+LU@%<쨾1RۈB *anfX8<ґb5 ;z|*V\ 2Tri 'p9O]ߨ-T&oO@Ez޶lq8qeܒX,ԯ'+(wU6$TL, 3"PBi6v!Ӥ6ԭSF{x'x:zM Lap-oyW]miJrJ hh$!vpĎ\!}'&Wr },z˻BFMF&kN:ۙ I1]}#I8OmUK5@*}B(ATc5J\bc(eXH;t!qƂƤT{A 4~F[`7I;; "Xh-Υ݄3D2|MŻX$c$0ڎept>E@h 54%l+irRU{7]{JxE0=B0%f.]wmhA4 L6x.1 NԴ\z6ZW|nɦ>AԾbvc?zɌrk‰<Ɵ=}:mF\ܙqb{sP>o%PC#6+"CYP*Ș.^־2<i>uT>MsuOR[gøI^O.%ذY<vѳ% @ .T?/dc+7s+ЧB;nǚB퓨Ew^Ol&)O,,Oi;s%D- ؚ^ހZxGbGކ1S\ǩ_n"rĮN2 [C$ xwwK r'ZYc)8U6Ll\RCw Ҥ\ԍiXeԏuQOcLOwm 5?_Ba)1[a[#kt]n`i4 LN 98u(s&#F7Ox8 A=Z!"A$9hm}3]ā9_ 0@V!GV9WL?JSAEjҔBỳ.6ĶO*˱CHOAفK߭%r9;N^+.B)H+|5 %ѧ+8WJ0 L(t󴝷,嘡h%k0WC?R͞cW#U/~@0lC\(;t#t!K OZT ,dNt2a޲geC1>8$f?CfVCw, |1`)}UW4ZuM/;uٵ ܜT/ߜB"Xb/CLѓG#7+*بܼQLYLJB|wbxxӽƜ%n)=V V[℞mMvP fb= C Jhм4* o~.ZfAV@,hr&mn%C 5'UuĢy>,ΆjGRsNnJ:Au]l29[tѼAW$Yʚ8pP+\7zt-~뗗b;G^ O\K8P$boYX~oIU`̀n<+ʼn㏤@WȽغ "O"ֺ%7vp˭1 A#0#wݜҨ3x}YAEl.HB|[D&{kh4eE8>-Rȑ;;'XĠQ?Lq;ecJ-z~CO vй@tWܯU&Ie/852dIțF/U[W6Wl=UpY>Ƙsmn ׹DTnZ)m Gj|J5D Wy%,#zgk> Cg2M`4dDb t>/)1MG'[:@zqMG}f(VՂqõ93~TV}T1O!iHѥ}wybJ_7 c)]9h؜HSpoxs)hmùbWq~lwe9sBDCFF.'v|j~^7:jq240jP*qD:<:mż-8($H?1[>JKYJsWńcQW J^}\iov}R0ƒ!xb\_C_K (:mivjne%@ȑl-QFOĂ G~D!?S5n%M sagK?BaUKh bAO?];@%h^u<<ߵp c%/ q<.-D~[+&W}CgqoEkͪZY0lZF3Jho^H"ǔ4pwdؓĂٟR@'/ ⴄ[0=r{VF +؈wC˯_<3 QQ2`]rL>Bwh-;DZi})r/P8n8aN-/g^Tg\0@_BֺS"|@V_-{hy|IxpU IHܾhlFNGq2.]DiRi$e KB묽jBX҄HͱuMMDbJ%PGW'!]D(С 7=gA{ L*Uމ`NWZGvӽ I'"#.Zxn?-.$_m!;YfEC6pJQձnȐ17f &H킢E Hw}9Pi>T8Q.zX+z^7J\I*K3C K{IOҵw!H3}hay= / hbR仴ps}eSV /qu^:,86It_SY0tTnt2FC%83 qٽie|Yf$z^o֢/XQSJ&S~bܢnz@YOcW0M|񭑽Aб~a2 _O{q{T^\͜R<bQԝK|͓f37]陵?d*4dg;xV>:v& m B{*.M(GJ'Z=0[8.cx*&WP5nkEA9n_Ϋ~Άҩ:tpu=:+"Ҭ77gg8nNZZJZΜv0*3{u۲ȄjP,2>6& :gl.BQN\ ܊<[g!L2~ τt`UKʩ fqMMWȔ+%KK.A<؋Y&F ukqqWCrnn|ɹ돾 !$ TtyUپ,ȿGZo)׀곺%QXWAGsgG!Li.+d>EK šv`ԀXurY#ˆc"X _ikUͺMqitJfd 6\aX4pX᪉ZF}`7:!T6_Cdg '_L6A %fČݒMP \sK4$,((Qif@t0gEx/51ZGj&c<ۇȢ?NF:q36op))K*a,'[F10h`zBY'\Wz 2רU ]ppM>8?<階FҚ"4rjg'V-W%ݥG\IS\/^ڃbېHfK ^KZ{N!osHN^F"+$77H'<QD2'mofbZYN.=VzZ%N~䟝. h؀x*5?ߩMJBŷ@UDTȣIOVԠ+d&9#K W\9 !]#w"ޯ |ݭLa@ri%iQf$&"K6I(AM r<vYӊ5}Xe%=xJu#Cɽl04;*E)+oS; 󨰸k ow'%ׄ]N?Al4G 0.=0Z9vTTeZo'J,Y9Քz鋺*otvoE}ZQ;;As{,T̼Fs OdIaߛ8"웃&/Vڞ Q/'~>]$&/\ 04oCakl EuIA g[䀺ҁR[@W?8K'e9PLƔȮw@ ), Fd+x P.8qj[ݝY2@zipM帥O~UY2'{=ŠLI"w*6. C  +02w7ͽ61zW&):܊,L4(B 1s6S.>aБ5+Q՝:NfHEm 5m6QK?y,pDX1+"ۇP/M*#2X_yK/|qd~.=JB>ElOfHe"GjFE!*]6OuH3uNT!XJh%vv4LHVⳑP=8" Rz̢s_R;͏q0.VO2܆Jg0}Օ+aI' WT&z ar1[T#ܾH:5B[Mg$ ]ӌ ۬-x{ G];B/fa%2 k6 O,ژfo~8r_w klb<wVlszGIMUWU|*YFz=Fm M@)'P {V0i%O5+24vdGRo !݅ΓlY(U!bN$ %n .PV$`LЦ:Ŧ"A ~Yp9)gP DA \@ o)7ʤ{xX)!1_Qm)Ԏ=Co(qPn'+O{y:?"?Vク>KW(\ȼ C~^eclgpgFǑݑiu!3I=_oIʺ(igDw N&GzC%qfÐC "6s5 k]eצ5P*z[D=K|?s &'.A v?we9[ki95{sA4n&a"g’#eO~nTi%+3\ՆfkˌΗHZqh/9EECZ"Du'_ߩb-9rÅp SΝw* Wg`ՆH;a h_wszʗRl>b,r\@gK>Q Nz/ït7&ʬeFcIDjJWw:є-k K1.8c%wznT| rc/; &km|]lMtj-sP#1BcRqyxsw7uC&3%+f~FX-$(>coPCYXʝ(Z#=w#A5܂rF,~4Qƙb3Ar&Ə7w`<.м- B?s zWFw0xƌYE@Zɜ u758P^h _uyפOTsk)>d|AvakNv%_) sAe k|Y&Ӿ$LRF=wCl$Ϩ w_Su*HDSc -ewGZŭ w× qa@m)HƥAG~5(" e LO{80d  2drb=:Z09 Z92MwÄ }N.-hص W*OBcP$8 |ZtZ,;(3rA!\M}`"NZ< $'NIol]+$^WԂ1r8oQ,(趖XkiTĪ}T.]Y{g5NK t 3WI{j@#Z r]g6IYeG0z"ړpmL^{y04.zz"D#^+uġ)2_CIh;bIbڨ{ `l"7~1>}Lq7lX|Jo(*ϋHE\/`Qbt+ldqaIb"یY |:lƎhduT&UcMWOPyv3ɴ)L'|bl(Gn*ؠy>5d8Y:AeGݺ_\S@$?iWkAo!kҶj5l0U $k;X^.U! ї :^_T/PlzU~x}oHS4|ӑIwS;DE ލAq\VB(kS_>t rA4IM.^ /OLpq75 4BNqdw61^pWdt> )EO4%}Fd-{ 1ZAEn#a|%>s⌱ ߁>ӌR}" ![9QuM1 #g SHŲÔYCLƒ9\'#r(B)kDn>w}̅r9tP7)L hfҽSCհ"ҙȇ"@BUW(+l4%]8^wBDchqVo,;YERb2V'm}An sZ ] *ßL(E}&!D6y^*I:o;nF0za- x-B+Z3Tɇ'M-=VB wQJ"&y`9,ʞـ^dg4hܽ!Zaڢt_ͷ3%4|cg+zq%*E 1h (O˸Ѡp}rY%P?q\/R5r;x\顭pxifWI;}jnޒnbE*jD?4)-ɻt-4& ]WuٱMŶLrW/Ug Nܩ=:HIFrM)H 7;q87% @d5hO0n0.#1qC@Ճ́$jb岋"*I|ɖ[7nT|Ij"COR4lnr+Em\{7cQ#6BL *5}}x0nts;t;?0fwD1{|;hJSpÜ"`p~fF3?j~ dGQVV\,3>VNLXEjnT; @rOY,?F5Q|I]p~b4 pz;`UnCgԀc%9(W-zZ,RI>S)vM^>NB"'Q=LFgm^BQ>r +&e^<fo6mʔT" FHscTmB=3Nk{l(sʻ ({R<@l?9'*HˣUj}/Vb$FSf:R  |l=}O&s6\a 2=BG92.My=8DB/i+t@RMͿsU'VR>{IP\[;O>RAS 3|#ʛfe'P ~V0W'683Y>H6 ;*u.7"[܃?NIF3~wn,!5Dq eG8T٩s>أ&;U^E!PR7,@06lx$1W+&WoB6(KP 2ċeE4]\qɸ@M!0/b6#.TG:zH4(a? jnK6d,A׏Ҝry{,;, vWEv`!/݋auA93M;c2Y"}'S*spaTD Py`HM3HA#×F]oxw:nUAGudu44 %skK9M3-0ZɌ+ΈDUx4qߢX\-T(a$[YgIݺx3CsS(bؾ( DfHVnV,{FkЋLK׽xLh z^PR H #u8@UV4}v:,]/3 *Ɏ,҇ (Ny0l}ݘ.D+gW-R㱱Q,}|;QSV{>n%~) 'sD*ϋ"#f*[M5ƚ B5ב`XAk~rO֭-ƎW1vds+]Io@1g=G2(]bTj![#MyHcRϳh#pйir<[.vŗ7~.QL_>hfpqݖ2F mF73n߾AXth~X |8&4>O0N8ψqZr >7̷yշ52Jrw4zλ9IXa:+[++vvt \(Cڽ0p_i7?ݞ3 ]n .I*:fYڗ+.BnC2!Zio#)ZާTsw@ }7}S(-(%*CM;~P79h"@[ i&XjHvxbK +e`Bj'3dv ]lo=ҷ)bWMHX%aDZɬC+,XiEѺFgʫd?|Nid9N;Df)(:?WR~gNDͤ{!NӦ:\"z^Y,-c-4z -V [UJjT݁2hRY RF)"㰐\z`&:}L0q!.GZ%Aukx \O}CnCT6d/73 @m$r[1"s )u8v פ>{mNkY5~^QHO!dh%- ʻJS`14zɸ+-#"tf1 U 8F̦0ٍTP1!49]Y *jjYd:qPZ  At¦jMt K2/ Ӱ&͟Φa5G~u X} #X<7AycJu-iM:(Ѥeg%c!O\e`łvL93nSuH`?zwoY(znwD"VۼOw{ݬ ۹G`T mM䷘KO9f)'cK5Do-Ð_}d8t3wq_@zt?r~(A/juRG)ů3cmLk!Y(cnob()x}%.[{$A+iå& Nv,bWTnF{UBl#ZaՍJ!T<1I9҆{I?M%|98^4#ݽ8ږ)2JWAg z?`ٙ@g7Ыg_g[`~fY'jx"ۄj2_jp4|G)+N<1CKxeUAI#J&a(h~1J?R"sݾZSq-YӶBw_{&wX݆:-JjJ824 HʱjJzNF sYŤ96}̰BF q,)X蔃֫U^F"/zmb߫sM]OZ{ZI6&VY5Mƣ-;ƵފоHߦLfZBvq.$ZkI*MdoPGK|yܒn#ܥ-cݳ!gըb}ɿ̜ ׳|P}%auXc699cAq`w@Yi!:7JGj aX@}K.l6EUK/5?`͗J֏M GD6dI|='FHȟGKOE/9ɠDN&ğT>y~Ϣ;j3vcfH*NHNP>$.A!@A#ex' n~@K%?U!T")F?L&rOF΋ GZv:,ᾛp]ߵ߲13"@B\T KKfݰ,7vꧼsmg>, QS*H.\6a5 s / -> ZӨp0?(0)mvV=an @Fe`Y}/y>:d}D_B, Ţ<~ V* r$N2\zgP~#̗8џNFSS0E=cq& M: &(2,U?1jg&u/ ϫ٥ؤSP^0׼t'&IBn/]6}Ƚi&Y cϼ/WZ4 !FMy[i|+.XoKL58c!~[W%R,@+.uz*ýPcM$W7[\m˄s: / )\6zTN^=nK̰ H)$S]%"OC,/Y@ѱqv4}X)83y`JU֟:_T ӧڱ"4>mcV:N}婒(! {#D;1ݭ&S"S!_ CO^NO{2K #GKIf#&B '\.c<]ѤUJ0ŝ;U P=SL~tJ`ٜն0:U-NW'pS.BN%mUazT_?vk:DL$cWUUB[Zm TOs-|ˉE4{n+KWIȏ1Mz͆Mf\$=lх@ʉ0^)W* U06%5 IYBq(>c@1WFlݎLo^1] ٻa>l |dMuy]oNNWZBJ,Hd˩]bVyJ}Ζs!"%a_^6i9*[S8>Qx7:x"ƍf ?.zѼ=z̸'Y Sdh3 /!`o5m ~(J@4+Xj%1p\JB-?Ͻʷ]kͰB6JvzfHrzM3 ⼷8w? #/oD /"mG%?=,W&aվᢂ:wM?M7#OkveLteQfh9 ƽauȒ"`DYaƺeukXPC# )*M)"_hmkLll QZq5eX̉B6nů>J}Eņ춅'XhS<Ճ&~c2j{[H?Q(bH]}2\ء@XѼH|gDasgO`/ ƥ5 z#KÅtRʕ-%~+)o0!o)ej>G4"}3qO]C>ӕ_d~ARxF!J_!/rD⬍Q]Ą+A"s)~·1to -v&q_ p6WCsvz "1On|6Il8.n*:u+RSUDZ]& =i<R|AYl*̭ui4Rw>H ."`}Yo䥘bߠAlh__G?)5RuqfbKPihy+y8$9ўŃ73j+v)>K6? 쫆Ҹ0G:*4µܘoxk埓]-0: I}'ɪ vP.Et!a+,#,{hBӵἶXMyBz5S:< NS]<6F]4XL.F& JC.\η=M_}X l9u)x + 9{?#M12 )Vx)U>.k9]q|j(<@4Ή跐4`Yz2<|~%H htK*m`C8'v\cuv HnlO⮴`ka}0q9 8AO;_lfgܽFfĥMfL攰nmJ M+/՚"BT*#I4*=w݄!ZToLWbLjG}zc!!M v9h\4,^-l(H2jt}H[Hs4{gn!Gϟ8t0{x Kw'1"Vl-ZR̈h@$`h쑷-yNyCʓOÉ",lިlĶqz5M.€E $DLL($DDop"f}#T#cW6~JTXH0W`kEHJ띟tdTj Y#{x$idI.iIT-?L:rc]Яp9Ǚ!=uysEALy`bظְ`}VrrM3gjdfX 9O7Gw3/ E3crmm[t#NM!]G׫^Q}&@-7  39'ӡ i}YE}B;eh ]_[)ևI/nuX7hϑNԘlȠ'\2m#e. o-e*!-TL~OhpTdvMIhe$kM2,ڿa<g#_ߌc9໾+xDr싹RƂ~%5czD3"Oԓ}3D6iLhQa€N4޹n @ejfG.` "_{Ȗ<]2~N>12a&(T}t5G@!]k[=d]OvV⩦v .~?d P!f\Ry%h z׾^Fِwn\\4v]-|] Bg~t*KvG aem23ha,mZ̏}p@PFT.K&!Vջq19zA:@ ^4q1EB~7Sbꁳ;9 n*^KJƚ{JPQ- 4z}_Bqjwb| LٕjE,5 K_^ ]ſ&4#dPwF ߢ'eCIrBh#{ SvQj@7KSS uȤ+>v1?EtJRQOVz !A,U{`x{l٥:tWMѸ  UgTq=yxjU8]7ī#cyo h/E ȰHٮ(PZ,&> u fCpޮ&I=(HL`F+c9~e7Jl)CN+|tt.t [HvuhGv ÓzD̎U"TxY)UՂAτ F5Ia @b"Xٖ*`7rai]ŋq~:@Gxy'&y<'`$)?R]=(oHղŴ iGHpP*W 9/y~ F\2 Ǐmv&{p15REH*!@,8~41{h[Rs9Y>A?pPQɐzj5ꍶ5aHC_ {xmZ):Dg.=:ẸBbFgiR Zlh%)|X<\l\m?9|`b$'m REz̯3oycGd|3ćl<7Z6A{`hؖ#1&FZR?4 a)|YE,?<&MꂲgDKD8`HK y'8hU Ė.SI;5߽Q"G'P>I! ; 3QN au`S|Tj(]gcVh3p96^ĕ&N$bNڄzGl^'#JRȑZg[,9J;v:6 9"/͚-8R;e/=`R-<tmhO b ʼ)hmMgvHZT< *=qҦ2$sQ60c:vhf4! cx0Ig.9M6~vƸ6w04jߤQ, 6@}EuGo1VyfU#[,8=xe d1ttKyp|dd}VF݇[kDh ]qS[ aӚ& E_8J1F>݃W)s6ԧÂqc_ ur) <6g* :bmIۦo67.hT4>&s] yTAaY +!.HJ>=82ԇǡ\T;]OjWv>v0'HLBZzn^j$XEzv[N| ]>PVF;8]\bHKreΡ`]se{eZ1VY$Fk`a}1RQ(ߎ^i_ Aq==fH&eavsuGE cFFItz`ny~ms# kj( rS|^!1+t@4Y;X?0wwAauN&]ΓGXo ̬>ϘA} ˪x\4j0 p6&mR+bJ{R.GI)oB!WiX_<\ڶtAh\ƪ̠Sَ/ΠS/ CdX;imn2FO xA@@3e-F#WvH_c71;xW %Sez~05Z'Qr up#p෡\l5([UjcǞN R G Tʑ3m CWk4 њ)-j;1'GF{28DJ >V˄H⼱1yO%ߩ.u<$f9k|X%WB 򱽆p'nQEّ= j6&\1?y MrAugu7Z6׭=P9HpHM YІ-`}*;Za;$y;n |ɞkdSvN  ݸ`aXiut?lHstraR m#™^P uLJ'/̀\7'B%ܞ , EJd5]>Y#$sm˜^+l٘ݳ'_P3m&b@͖W08O?áЄPftz+"}xeĹnBg8@lE2]=O]”|F\Cԏ3B_&`IZJ"%c2w7m$=[йJ&$4'8plSG5ʝsPj;[K 綘 dڢpt{wδIгµTW,W.9p6~?I4U4$lbݷu VdX6zcZ9Q81.kY|QpcHY},qN3&QnlK)RF6F=Vr.,gȲWt6b#nRHu˱dd.e5ҥ|[8* ?jG)G?#(H{,!{11aMƷLpQa Un!sc>PUkZIZ^'1dKUA_ _br0b+eURv@u5>jZS( W-q7aXe"Z"s%2c4.z#F%"h-&i ̪y;KK4O{Rp"U)>`Q92(Vp&=!yE΂AP*/ɡN FB귛" rY \_vAb*b m_lx֭"j@Ж:d JٟpbM^d:go3u$Ԅ*a5cMRF6hpjZ=\DHcSݯҦH㝥/*|"W)3+p}%BT2G=1n}ejU$5I>Q( OZ;>:K>Y5>l'@WgSS⬼_'>MWc:=Ƭhee{lϠ1;M̵YqTuF.N&e`UV6EmW3k|w^)"ԯIIF~ a{T@M89?P"3Wty}>(8 d\W[+Q *mڬ eem p4Apu$(zCK$wc0F=х $ I h6V3}3 RAQ:6Fg^Ir0rK2:m]5)uym \(w(I5 G) C v,#PY3AMpB?{Rhyݴ@NקA>H)K/k(]Ox` zY6[kC^`sU{ {6Mjx\3%\G^0c Eﯘ/H/ Np:$1 .׏47q1"FJ` ҿ>W_c%NC"w|:@{Uo 2²kux'Sw|V2W ho$asq౉vYc\fEN 퓿CLI9!ml!Gw<a~D@MשW<6&E% p]k/>5iś pk?Urer nQ-"((f!3lm` zX۸ $;g{bы7NjPbBlcӾ\X'c=+u٤@ ONT3=ʖd(~(ٸ* 5!g 7K[[ysLL>|T&K(>|6y'g0uWV{o }g4SDQ-'% NK%_fցbpeh pIt&8]Ӌ;hg*[\]]=Y2%ZAv=V+lz˲~Rj|ޥ[A2&?0L<Ǔ_رKgec9:G0ʻ]e1$Tx~`Gsc \@D_JZ:}ʩeev=SH{ E] ͛bnW c-ڴFKV.;"& < HSp(=GFykZ~Eg>hoA &gq[\吝#rMgT7`AD}S؞FjS 3*$#A@+.C%b2_~9, _&$~6^F)B ;&aG6|xr8gn,5C^uںwT+`XO3nHs04?w6BuC|rƁGVm,ߚ8gu(Ք^m7k;v70QulL_A}]F.FABA:XnZ?0sl՛>uHSA  .:1-ijn~#ȯ@lκ(%7Ŷ(2?cZHY #ȍ>%;'C1+*H&8曗C~?xʟdP<3E DFm'PYsfQE63P1OV@Kb#TyTAWujRMGԯ@݂a\J4epNiQHĊkOf8ĴI; ϾF's Чs$:DC(A&7*otHE)8Br4B Cxn&t=͛YR[تn.qPhzwbȩ&Br&^[Wՙּ$hOi1!Ն.P-_ ,3& }%Qw9|+ {,tD%\=b*r,pĽ4:pMAч)5h?sk Jmq=[b3c Z,S}ޮmIH[ke:d 3 {hK!yZ|s$v~9fz!QA|f1ӇYt\[UJ(;6aJxܮ{@Q#K|jAzJ߯%0{e/$ aG@{ױ&pYSj;̇bNC,t=Ze)ѰpFΩs7}Jy /~Jc5XA4,[K8ξ.[Zэyw; Qp΢TF 'shxBOr54)aTZr[R_kmS )i\أw498UdDOI=d?Av0Wj](5]?!4E!TVĽϧ BQ끆 Hm}HsD?"f[D_5z1N0yq|SЪ7ۆbWCəg>7n^ov ;^=zi`)]xihmcND]f:r}Ƶ~ u'cGKŽIUvfXZs~XʈI3OBb!mI+9 _$'wD_, akx]zzeWD{1w"'P\[C(bK})ntCEXA\:ٲ^y nIMX`O=4fo}dLcy29;xٞB.`>,d:$ KXBix_p \׹Pćp>u]1ThQ$[j&fk1sz]--*_dDEZi2hiO@U#(.UHc1S0leU<+h)kgiOo$aS^9[<ЪN9e*2F@Hזx+"oZCHBj=?1awͭ|N%uKv2IstdS:~ ~TJZUdmD`jӎk(֭y=C]WI]KJ/alC+]!= CRO-%3n*z96T~,k[#tȌA&T(һ7lle)"gJW\Or-soms@o%d>cK?s N-^0j_ܾ1|մY;"\ nQR"};RE#-ҝcNw}w gu30әi!uP%ҶKA~s2 Po;7`z]׻4s][ǽR$Fa h70؍nx&pߕ0/ԝ@w7#3uH[fj7+9X({Ԯ E;PECjl|\]ľ #C#QT^,i 읱{f$N1me;XLP4g=3?Lmkd5+yTCyǵmrX Ͱ"l" {}[) Wgx86AhmͿ܊GoŇVNp64e2ʑ^ȦxEOGt/edBg?T7NZW<%\f9-I˹I6ϲ[gZ4$H NcIo Dm}'k]甯KK}\/muGɥgC@ԩ,79} Vwɯ3?B3+=3 vHđ|DP&3@r4T•M,?70 9bEMM3ȏ^qtuKA rp- ( ݂P+3mM8IbBPcY}VIty&,}ķz G! E'dx1% U2).MT8ЀZ,(GR\ JmP{3 ivQ$6]&ڵ/;1PN- s1Z?ixf {EF[!}zvbZL[F̫QCw;@ 6Jbh)JYD)?vAMqoaVg0\^SS +tVSIg̢pmm;UxDe@֞Eӹ/(Ӫp n^s}vr ڶ)"x31l_ȗȃHOF-k cD~l+nO@~^d5E|]Jjbb]T>+fɑW([( '"4S ;$R-g 6ӵ/'8c fE1ujX<'}P hEcwMm aT6Yĺ{f{hK{6T<ݹs|7"G.o [>J6o7ZF9!ONxFJGh7R?AG[^*RNy nM?XMm6U'NԴuLr)۲p thԨSS\U#3 @n 4_cIݵUz:D*'[A.PFף=ýןtڈ+UF>ɀF:Z,) j <=+#yjX.-6s;tpmk-I ITI+Y1K ~wKĶ*|n_80.GeH tjI"w*붼{W5{0[b&AbbR erGa_uoŵiԹ %l?`"ֲڼ@vd_/2̀O |[%H$mc~'V5 { 1'˄83}xF"Yr<'3^:冬Smb<n 'Qr7(oBl٘m,>[LiXp^)']`s*>6u>:y?7(*EU*Z8'3@Kq!:G`]G9 ,=@! KbI щ̇i bKxr"C!hG,B҂2_iX͑a%1?'zk}wfR#R&nWJ_6n"B{ lSI-˕+‡ X=mY$ZJ]28|Ӎaiɢl' iy,)L$ (r)SAO#TX+zް?tF8 rd^QgF AԞc.}'+g ̰RP_.bFblt8`Cf8ʐ޴]ezL^Zrv+Y*Q֖g]}y)-9\B̰rr]nDCvb"gJ`q.{+))xb)$;B~1O+c[R1 >./ȳ eWSotlN ފ(V}kER\Ioܸ\9=|u7~fboMj~iZH򳸬6^~@+'2ܨÛ!%:o@M();dnqҖ-BSeHAXs?cw*613 roG'ϒ&_5^sho7}Ȭ ?O[0^ ޱ[ו_m 4WwF/ Åԗrd;qx(U<)1=_l ?9>WbթRĶN W}ǀyH@rcA't}*kdĻyCGvt[[e٩!j؟xy-Vl/rɆ{#sS7ZehCĈ-~ܗgb-\O~-T] d&jY䫿S58ЬؼHUw D;cIUeF>lO? ZkjӋ=FZCD{ڛIz\!Y<3GK¼•Rl3'J#$WdSCMk2wP"QNphhަ-H?;A Su>B $\X~T9xF*',(b 8eKc{LXw8vAS肃r%l .,3ZV,HgKd3-HPTWSnS=Eѷ*ز⃭Bof!'kZrRyFvv^&߄L||k#v-D0dv"R{~&SȅG0QY[zcZtz`+uBikͻjGa`j={hi i5ӴF`J' k:c9ӑu)pHYHoDY#;N֪Z-֝27]3W9tB" j_2V$F*`ͷ[kk}|o:zz j}хiPEB08wo ®KU:h Iv+OYg`@=䖋XeWO, x~=iaTfg&bch(淒; Fs#zTZ6b9sY XAD nd(l!+}>E׈e >'@0\iH2#r;̈́:-"qڠKӏ3 LS"VĬY$bD]8#yV2&Q##Uɑt!QP'+='=e*TKX{:d~n* Ó9ŬMʗax-DnөX3}Ʀ]ſ,ʁkUUltd3BdqfY Y+K tmtMTtLr&*mpbJ T@n\)236 rm_9[٭ ]N 'WdQp8[=*e3Ƌ>ˉO)~甑ȩ.: v#kA UΆdmBGuwE}[LK)pUm vlޞ,:s,Ojتiv,yJ$K|Pǜz>}'H9OwW0XC^cBh(s<090{s]#YvxH)-r;T3/rRru.dfR'/IC&3b0>%gIuTO`YpI3 nN@XMv)AɯlSN̨"b0 ^G1ޱ(&:ҊF;'# "ֵEwVIH%Et|Fk5 2C-X:в@,N`:ry3'}% Z 5K vڡ P| X%P`!Ri N1ch`xOHt=JLVx;&]7[.wrEQ\U;sGl"9QOb # @,}o {,(Y 'tW5)LȚ`tgd| ıO[M;w=%W`=j{I0xr4%;xگb%2Ջ=xوhGeTaGI: _7NJKfj :A[a_j֔` ѠNW]ue`L~_Czu)3#"ǣ\@|sw'Vcg8!0Fhp;,H[خn Cv">Dըci ?(֠ĦqϏˠWZ/ F #Gf&6_r᭵$˸<ڡcc@)ƎiŹE?j;Yz>޲a`K "SU'=ڤeJoζՐY^.ǣnȣmd?g=&P]2,O^vR ѼwrsӾ̄\`FCz5u%@k,'o,oXSi0@OCCDƮSKv%]P1:"Ox}cu^b Q3&IK!XnoeNDlWC1sRl. (;.Z  d,ZƛBo*2wa6y4.جnCpmpaݛi>p=,܇c2kd\$Pj #MtKp'69**,O}%&BZSz|vϰNeؕxچ:<ئcX@)j2:0[/>HjBkH2|?va=-3dX$R2RIK dy>0q0|t6f1}/p uCp4;a8.ko: .;os.@CB "fpHzl.t?=mY2M+4hwdeQjWpF"8m:oQ|(7wkT9D? v=a(3~dGHr_T?dDAh$u0OjoFшMn JI5Uр;QGZ3 zP:zW:fJYWݴTn*G85'l!@M<(K^_-HUC^wO=]v-ۻa)$Jnxݕ@wFlHmU1R5fr ;~KW\Y k EDbmZhj=r$9MʁWW-ZՐg}3 q'QE3msSP7}) qpxWb1ի.Cq{#Ò*>˽ɿCh0Bd9ٻj,lh7T&2_z D;P^C#KA>jي֖.C`&q^Wp6ѕOXh*7?.j@G `J9 >En)UH+M("qLt̘ni 3yd"Ԑxl]qT/}r>$7s¶̳tSEWT5Y*m; Q>mEiJ;t&!hGR`' 3Ah?_nѫMpFH]7Z˽rhл#=!~w l$I@bCfڱ" ,GUU?Ratw؀W4 Z!{6k yL<:KıE(HHχoESH+`k.MX9<:ܣo^77Bˇڻ])"5 NJ M`3mW|'p@SӳLwʿ|Օ ojED9N{&jm[tN2AGm]/L50 JrKu>ta)#LT+Kd0_}!u+Ī^(>b*ẁjuB49/W &gN2ߠP\"@Oϊf=@ܧAU-"EW>C 8~0mtX2!)L9:R !X_3k^]5xjpK]}}*5dF2ɓʨx@3?y w=|",z _iXy/]BnsEZ6}/jRq(< ;X%&dm**//& ,{eOfZDtI BY0֜9Y@{(cp 3")iy( { 5.t`eD/ =m ݽ̹`D9 KiRz<ÒARn #6U;(\`ؑل4m* t-v?+ݗ _I\ڞ m8SW?XBDK 4;#sIϊXm#p[O^xH+gPdEl¸&+O(v}D88jQPՂ#FSudFri$3 Mnd@|48׃2nVx<)>pwqt[!Pm.gHl}f uJ(ġ 7XJq> %oI b q.,ywn!JeZ@#)JYȮPgKטsVQ Rq3K sNHXE7a 07\ӐpӲ!\ґxtlj҂~%Oe"ņ4sf (C&ъ¼D |/N% vgɥPB_ȁ~i_j(_$áz LF3?k gALzmMe7¢8Ir7 e|CA2VlCTc^Mr3H:Dy5(5|3{32y$k+tr*2bsuWl6H'!-+.]JӸ1 @OZw<Ӛ!cI.,!pgF 5ߑ!:}yi%4 z>U k.||Um?;/eޞ/ # MOTXxd^3vVtP=O[=t>'G@v$.!&> 4cs5Hny;bP+W n90=γt,ϟv`OvKL%jJh(쁡 $|y#xtʉ3*twɿҽaeMu]V2hUz|P2(9*7;*?T?` McYGjuˇ搑@K:6Ԛ@fk%QO#ZW&#&SzaAvTA|AÀzҦ1)5z 1Ɛe"SbYjHHϦXQ]8p b_i# A˕6J׀.>p !hע{3Z\Zel8ze*KOB/֐,_vޕLJFI&hI/>nX[%%H;!1bmCFۚ"HqrMI6<42đv*@&Y/)+H;~:,Jfv䁝W&arX߿HWs$zvd <*e\b-1%w,U}ECcqXhS{ZW+i0tySr./uFn`.e0(ݖMfO_mP`VLw*FA.8i-;`$ć{VJ'M++u2YB/ۍG>#IG$wyBÖg=h3>gx`S"F55 Ǖط7sd MyBy q'"ce^J/9A31qp-xc6$^v ״腲‚x qV ͆=Jag{KLܔ+g.҅]z:tX,aA@h?kY~1hv Zм2:.qt<%|Oe%^o[9&CT0LSXRD(^s㎹_ .JN;S{o}>y uHd"Z/ 'X7v4or3ȵF)=8BEtydFg۴jkZw#1sH\ ;޲2!k(kr1-CuɗwԛlĄ[:uU|_"/^/f1݄2 }iN]h{/hL>@ŸrO 4I@2-3OCyHĢ&]MnQr rA=?VI91H+sXDF҇!Z^Yg<q ZlݤA?_n% Mv=*6T1r!A߯U#j$8P_ӃUATM̽<ݐ; "2DtDc>ϯ<2oUnhn ?]U'Aqq,q ֕3>Wl'h5,niEƋ..9{bU93X}Et(Z/7n;:}@`K`-Ba'#`l-X#R7N}jZI\L'uP'A_"Qc~u, uHUG9J}̼+Ҕ<3KDgΓL[y:Q Mi$S)t'ɻ<8~YVYv+j,jZLֹoFQ58.y,&$[nl5D8*M3IIV.';@[ <RY <oܱ(lSG F*x xh ]'8Vu/ǏJ?@7a-HhImC|VU)~ oi*S-?;Y4 >wB8{n)B9[E?!? 920EQ'~tHtq}4 % *R΀V)k? va!ʌާJK;;ә,Ey0Y7=,EL'ROݕ'>օ^as@s:"Pt `p=٩-EZՐME_\;.B `OORUK/+Odg-!{DģWyԚ⸙ a1S${8wF KY?3~cbF_sX#lyBε`twsQ=Zm-9/vk1r)?p-}]dW,܋JpN.1Jە1MH, \zz)"km܆sP^=^kA!n Lrg#$ɰNJlMKs g L|'RV^0<{7g`եg`iI &G~DEI1t@ YHTNbovU]H퓻1Xg YQ.i}n360( I8MZ+#2q+X\T oLd# 8Т M朞kL>ˈ(0;j_ eva(w)E_Px5S#~=c֓w;]b-]XJjo?!I'K]{.*8lvЛkr<,EuI{GaK*<1㺄N^1nC079HJ MQ$ U#ET. 頧5\Q䷁t;gʫh)_[HG d,l6Ƿ+?vaH---SOPpȑ-:fNDNCϖԾN~IuO '(:*}d7^_Lcs a=L^v0څm!RP^텚ѧrTCk7UaߋAN ZRL,ĥ8#@Vg"޾c[X^,1ƽ*n𨂃l͟ Z u{ل(yY_b;GLV+ ^̊DF {M8 H nIW3M~ rmE"91 g6=ΩhbU߼w'z1&P=,@mͬ0?ZqC F%UI灘/ VN)R3{hq& .E X,'P7^ЖGVD_8?4fAa?d;*Rxvª D(V"۶Vt-9"@;43j=PJd.IjVyÜ~nmfE0h4džW9 ŷTǩiMi!؝4ɷbAVUv#pqw[պd"TziNYm~Mf7SþBc08`3΂ɝ^4KL( a056<q~Tt~`̐C6.4.ytN,&W]zw+1A͛mHn H̒,Xq~q"-؊9WRG@SoưcpZ] G6 C=说e,_bQ@2}X5_- > ;3P(Pnlj_]Ejmba]̶ ZZKmѩ;ה-{^: ZZ8̶hW ̉`7Ӥ1׎3GMa&ܼw.̎= h?/.C^8x4SEQNȤV$dPB\^쓷阸#?]~2]Híe֮>H0ޣw0f=y>R_(I^ܥb hvnEQG[E~A렊], E`1U:*!4d+Hњmw#_z_QsrF k̆$vw $qٺ?WT\%ߦW` ϰy^3FLk⅜G1[I-u'#W.3&PpG Jw kVvm&XaF;7%$ר! IH$|wT62؛n' 7a^e3A]Oj IfX9<|bQ?迥9%DVbь_fZ%t"FB>X6vv;6K;OAco0lxwfC 5I:~[\ Tm#>?%7Isľ0̵w05㇟c_04kr`uxyek.e X U[]ϝw v aLsԤd7xݵŲ%ڴD%$\|R.9A2AѸTNso0a/@fQtz6iN*g?0IHXꌁXçh0˄/JZ%@"|td` t$|ͪs61r SEY-%!gy3L]c W!}|1I;{HZMy x?#~Fsnv ᝖. EQsI\xt Rߔp9 N7+g@ ڬ. Ə -;jJv{#p'LV יUsJ?j@I89r'+6߭{0腋\3sNQX F؍˔ qz ~S;ğ4Ɲ߷oDPL/ 20:A,Ah^埝 6Р6֊C+Lm:I~ҵ-h `έm.즏 ިդh7[d T׺^+o; ;Û/v5ډ.Y.-x.Eӧ6sr-Qg<ҵ-ٷ>N# aV^2q`\SZ ~!gQ,`Z˾s+&i6Ϟ3)@0K:#XЙBfs M!ZxJ"$ЗZB"Rg}G MD (C.)&ϙP*HXIpDVqB5t]W/lIg=i}\D|căoL8\,(T8 E .VXr߳UFi_[=7#VK921HN^]3a9+g%"]\ GwX~~w[l 6y]6>~_u[ ϮcUJ!~w@Ldpf$OhAI8c2{2>JWQ$44U[ǛاPO8"(CwBm2ٿZt[cX#xtfֺqSWR"cz!'&O Qĸ{oVc⣴>Vt!=Xcyݐ I*Z*@U Lfƀ==Yԕu'c $Ny8 (S:V&WD;/vɸp8ϴd3RZXQ>DkU%S.-dRMe#ȷ2! .6@bcj6\@>F97)z';թ6>'BGU" ;12%#3OG(d@"DujRsߺl `TX8#]8~[ KARbobpr  qu"R0PTyOXpqew,/"nʉ˄%#Zm/~LEQ-¼F #6D9,Dbw9JvGJ<\m%040ШP%e.޿dUՐDݣ< l-V(9S2,0GiA7]O VwQ|67ZIUId+~G&_oO- :]O'yRƃS#G~Y-27%RS F>3xuONKP9\aqNOD}h?[zyXrP. ei!E7=7Y[5HL-p-W%"h>‷C:S3C:e2yN7=+]+1lc!貨^`I ZADyJy3FY-E1JjbԴ۶#={mi.N?zuW`؉WAjW4ht#<'Ap1giF{N[Hk`ɻ kbH>zYh*wnA9i SVQ~W2Rt*ѝxN2G5zdž$۝:{}~Mbx)ǎw1MbdL5lΥ%êNi kTDWِܓɷ$$!(3ؐTllWAS`~uP[PD hqߝM=#)FQ59ߘ؉? oB0p:Y*jRgy{tADg [p]Ss)o.:sXgN[pacdҪLGsxUg"g"i>2!%oj,/‡/@֢ Z:iCS rZ6`1zֱܑ ـ}HϨ ׶_ ;rv.冃'JE]Iԍ4!%kA..VD>(["V΄40&ޞ+Q+§6Bss%!YmqlUhwH~M0XKީ5_d:gkB?Rn, B-itBcSZZZ9\E'\l|X ֥ nEf)m0I>S<<%u?TBTXty*=.K4$  _+v5ә;.h=u- i6Pq I:,.^)XQ-xweKΚHna")&' Uܡ[=av>uz?MS=qӪ2kuRiEط%-'GV)0[lGN)&beފʜk4euvb]*K^Y}!nhcDI\_K]#'8<㓫Y򥊧[Ϙچ[Tgv&b|J_ '#LIAϹ;;g5shpڶC7l8B^pяݳ"5J05.=VBb@uN#5rM*CYRqڢLdߌcO-Ng}e]/>Äu^n)߸!6"uTbDͲ01!?hQY]sr$l4&%!r5F fc?_H|?L\t4O}wI}C]gF3!ֽCu:^;Z8Ubv`PҒCޙB.iOe-XXG3;Cw+ XGjegJ6`U{vbM5žvsWl~pFBocmC|bJm[L- `[ KSމ:I?D|"d}\aƐ|5?DMYä`cD@Αݩr.+Ϩ;^OF5լ_Q6c"=XtŐ}&¹:hV$lpp,. { ¸=[KUd{Õ;E}V!5年VgBOdw-Fr0A37 "\'vUU^2,=Ԝ6iӛc:ڍ*# BSUJxAjc, :.a&20\%$Cܐd\$c,B6fy"}Ϛၭr\h_BY:qf++tz^Ыd](yr~l&pC/ փW`\fj+0YW?r/p8i6j,zbWM=}Kd5qC$铝g?z=PcA!뤜s!YTM,1wԟ#}+Nb^ɱNZK-oׇh_ dװP5䝉(2ۄr l2zr>F#k5ai&EKKFUƶx0.HU483Y]^{ >M~/\ITFlm"C*(Mu낱nz9 3ĠA` .HFfl7NS J.tӵo6HtCk'_Hܹzj`zFV75iC|u\cr ^jL J6C$ 7Q+0J_8boF$$H ~A0'T~@+4J2@ͥu.)]l5,(G16Smc'Ur4r֜N:Pv\)!lݒVXUel<鎐Km6a͐|v,͝Ci\#oPڦVĮUpՑIZ0X qRqg}kyCڽPK[UG]Zp/d#]/skXW_%c/t0f钧f?4 ߄؋X]H:}$ɒ&_;SMg:m[Pǻ }j̹|cӈ:!o;o4W2F#ۼb{6(q^ptϛ,\ˆV[xzy疮uu;a.i>n-CLUd|J5]|W]MCE NM M~aܞn4zF/<=g|Rk#P6VvA4MqJdJ[O8q&=ܘY}= 丩P` Yt)(I30)Q&w_![6<c`ȷZehFsrr5K~29g Yф W{lraeҾhTaXA*2 /u wP:ԏ 'ǯw2sl]]? IpC=LUw7?ԁH9yL]`wun{\4 9[ˑ M`.+5s<J>Pp`ۂ|gn2]es=ucz]̑Iv[bJtbd 9 ~ miA5{1Fg8Ag|0DcD *5&zLC|%+kX=q.r\#8")ټN U>؛d+h~52 _%WV\ӧ7i')!җb%ni^o/2 }2"kzdqoh(wX~v4B֭n[EfS(N#ZK~=ߣ[<ĝaU} ;09 Tc ^as{zN=: +ڶ=~m)9it'Zp=J  o߹qCq:Pq)7N+t(˭-a•=%>[R&*kz~1d@1bZ>2vr7acb?S Dk13өhRGKSVH4RH#\~T"%Pr5:VwCtT-Vk@DLܠLrr>lJyZ pCEb%Rb:nK: ;rP9l,W<@QI-JdV3tCA&# v?1nm&gFA>zt@;jL.Z^CSYD‡SRŵQri{#?e$'DSN_m@d!ba#S)T]~zۓCLIlLE:kV-@F^h'X۷| mQCWv9qã 8ǰ٬RVF:5#}ʲ 9,xcT Y@6a:^"UàDFؑ#$@CNp?.`;2x`[b<+%fkхp,ѵѸ3CeYpIyE{yN={˜䢉W߮noC_I(;@Kh4:d23Pbm:5$¯l*h^oݶhsFҭL@0\ a )]DKw1Ǥ쬌.(~lc(SNnK`Ox1Qx&Rr|mCNl7Z$>50uV+pUm<ޖA9}V|[X F\~?;lT)&?v 7o;sim]'p C9 1j${ nX×[[ } 3c_4W곟ٴUhPJ4OB OO0K2U @1m;NyV@vӢe@__ЦM[e>pT#aߧ)|fʄqpTxmʡpE,DЁI mR_?f [e >UO4XI`Pg3?}!|pݤԧ"<e/e(ky\AngQ?.Kj<@ &K}iS$F\ eXrT2AҪMq㥖ec"ƧIt=ST[|owQ)!M|vL`?q~%{ 쌆q2|\[p]EDWi~}һeK ) t#&or]EwvP dZ'P,>ayK"(wob;KЏHJޭfF|!iRdsE,dՌye䏃"B$U^(SsM͂ n^|,~LZ1sJN2=G,3|AʤOUU'%YZ^QK]e9R؛(!wm) T搥!Ƈi)cwG|@6"?Pő.LD(~&UzIgAupQQ>r" yѳ5Z o3rQ{׷[`;3Mn)lyJ61>{l+]bfɗ@ͨ1`(z/]z,>rȏ0=1 X}o'g`ɯtoA,~/GSr1+ b\4ՠH/QrJDbidW?E&Kz#Yh+Pو\z[rNAWŰ 5Ma]ƪУɪ],ܓaZ,=Z(@l3$5Osy\m0[&Ӈϗo풾's=B@G}CܪۇJ?qFTׯrpKB@9:i~pfW@e&'gAμqӧ\{F-,ӫL)dA WN;Q"FnH,l ޗĤѫ+XapeUUlu]_7-hcn`VAO\oMCIڎ:o-ngG$l( : kOkLP?-zǞȗҢ]v\7Ye$Lw.-AAbhAE#'~l+h R \"SlBzN LiTGD &z!Nk"sɹzI26PO1VQrJTQ˱J#; W MV/ ȡrB%*(r`ɽunʜجΏñ  Oge69Y.qpI WmZⰎM_b)g9 ]@2civt,lB/YN@LN6ҡR%[ ah?/E$P6IZŷ+jΣ tSy{ 㕚2Hkm!f4~ԿQAEܷI+Z_gp;o3&,hdNej+[?8JŗXBRDyV.⊠ϗwX12\qI i$Mx9KK; 6AkhH,V^{:`ʹN{5gwt͒+_1 tR 4Y}p>$Mb2*ZnQ|uINņqA]O3`yE-oU0M1#'ԫpųuFk7z ~>K*j^cz^MY^um7)Yp&G^r%7~٫Z*疠:BnifbJvV>աLί܆?9`z(aK\?XDoR.OEeTS{KS{cZ11,xޣ+;}d[Lc%-ڼd@iGyrdZY$7(d~'Nlevo9*KnךqӳeƂnjV#K&EǑ̸mRB^yΡ׊ÉFgLɝ'(%<*6fޠ(oQd'r@{SBU >ϩ\>% y[rg:h",/+\;i^*Sgd"3N<+Ym,f)m,Bxh&ujCT8@jJ9qm&XMC^ Uzd.=?b}w+s+CjL@vidEkf-,H|jD(Ĉa/%()+~SϬeB̄G؝H`W\{FɃDN3~ZO85| E1rMl]EkaS5 |$xԼ_׭ѻ-o<\o}ҙ6bf_7† =S$e E-,6~f:@z'# !iPE VNX8A0ޯktK,N=?Z!%|! ^ڢYՆ kYZ`VhyY/P.#4|!;tœSTED&ٷts$ G0F6EGxɂJ:E,`dWk=5M=&/ܮZ EҭU=&~ӜqΛLkrD )7 l( -PG<<52)n6ʇD qX UXC=%v%&Hln2AL$ވk{w4@m9|}* NZ6s8Qx`T;|PL,G}I./D#=yќ!YHy|ݼIGL"MA"/[B#Q&7t[aԞ-|#@z>S=2v9p-k^(X0>ҙyyڤV@٣Qfs<`;ǯ2t@jo9#n~ݞ<C$w!%>1[9AǕKF]}t R?Q>8sfxpDEw A풼-SgIN-TFѱAm$#Hlöc%XJ:TvCofÓ\!T@=7op+ptCi(FQ='f`iܪ+[9ܥ"ŏDvTտⴁH M.A1ŒoP}aW3ui"/fp !$z;?jCQ}KuiOj)\N˱;a .f91+w6qKM$%^,B`;K5aԔ)rR Z*Uj 3#a%׀,85.sk)YߒA}{V7.qCF{]Z@oii'0k.2${8OkL8qךi{i12fS)$*1I}{fWɽgt2 |P \ f0ٜ˕q#uѕk5! چpl}1 :rL`KJ@%p}$ZJK<@l6y%0݇Z/Y,Wx!.V3IEVV!6@S BG'voߔU5G!ЌraoH)g1 ;r~&w4یFΝy9 ׻Cj͍֜=+m } c"%66f9Wo<U>Jj9tޜyȤ3;̲9mlzh$sgp'0]^IK`G3%HNTr c8=c}y>0#=qBZz Rz-aT}|[]R7Ծ)H$VD%y**DC FK`ɝo mi?ckqp;u&;'DŽbaw{R=:y;\FA:>vm`U_Pk޸F!щ&} oWTyi# x2̾/J\~uf |3=<ӑ]ufMZ۔hzf&*xV"oB!Ju4:`]N tZԤu3K]$MRϘwUQڈ>GrOJ0+(M6oqgS2-TYV]E픽tS-P|UvܿpUJ.rx+Rž̲r}[ԁ[`njzkĽn[01͕ 0"X1%ٺ2<~.K[N/MWr S TS.*qb/$pyiZulpGަ?d@{=&n$N ?SށajKF}s^qQf\.Zj^ jUP &kW_R%@L]5gռNf9eǤGMl[>| fKu[ІkMkųZXᳯ^Fҧ81uIig#lGL,5ƀfd 8L񌝲)/";|N[Ҋ z/djhcqr> Z24 ]ߎk6Vv6͎I=֛=1\|:uRU?='MMm>r AlBRi ;Eay:rgp;ro*J~kS?ȥҨ$~W: C5;08ߑK/KNA Cd716iF㙁Ƀ5ǎO4 ӄ⯢4fQqV*9B)LgUZ= {qK7Ea2]t>*!xO̩J+kGGgcRq_RU%϶udNaBV}54j:}W6I 2{ϧ{Fm80(XC^vY9]qQjPmQ}k6^s^= R& HJƼl+'EĈBf D2`Y f ]%}~"\Q/p!sfb(y)B 6bXa;4Rp{) ?BaK(F>rx/5a%ұՑ:|2v kr(|C<;h;dpJnpSv_Z d;ĻϓEYNf:0@HGʣwGߪ-##g;ZJf}G0xK5Gá1cb_EÜeȚfO^~>ndϨt\!1b5)GtWpxr1:'0G,"sWs=ZH*50^+"Ѧl!Z: .ٮz31w32dh#WVk@z/F*=k-%s{e r'v!&]O.DžRK (60maL8Zoh$[5k*HT۸ --Iџ$2v%J "JAGߧ˖EMB 4G`F>9 t3:ء%ZŁTH<(JoW<;˷V;$UIpȲđqX TKG9]]8`J,5xjo\]TWؠ-pvK)"eKM  WZ*[BmnqK(:)\U9]֑L $vWD Tw@%'E&| CCt@ڴ+j^9ƛ}~~og/A>Q7uygZKtBKlT&ٿFTIؾak<4'rÝ8DuT5:%&u:Y*\zq1v5 w ҭrҗz6,_Nm32rh"Qk$rS V8Pg21q7?k:ث4d>#hjs/rZF4c/gEZ-\ u>S@ f1㝓pBge$`Nf`ӃGyNn{D΄PhWJao9]΂6D!#؜}50$v ݼVƼH& Y`5H(i7h.FM?au (Oq5H \2!2睖C+ٜy_ɠ 9 z _ֿ+[\:=؁>DlFJ71Ff ՗Sd(cwVǑ@d7TkOTowfbpBg0\RF&Oߪ=C]믽݄RG$:?oBV9>-Āx=^-+sJQzMΔlsSIj:3>6crOx]PahSڒӜ >eu< LH|Z^ݤ.+Y .gWhkB+uUЦǔ#x; lo&[./#6_10__|Oc\2 m6S;Rd Ѷ;"K8fRE-Dqzitbߥ0#llAȏUȜ?M@Հ8\#MQ8EO-d pDFupL(ՅgJ;F?0[41Kyt bQ4ZkL㎭gw6(;4GMgtMWUe)&߷ hDe)!inT#/00UN[8"բvb}λ d N)h-MB^V.($lIf4 #Htz!%"J c},0*>{4uəxd7?Dv*eI$#6]mKb}7sqeYEGŽ([;RHy4>@H1.wESӧ {F;tGB hK>5cr/~:R\Kg{Fmg:'JXy|=yi_s̪y0r9i@ jVxuw4_iYզȹ遮C+tM?M=]'PI=Lh'Аpa gӲXzi2[OۺAP6q 5B JԃoV#B{.][:%;rA;CE,3KFQ--/bsE5-S-əlqVW[jz8y,ރPȊ9*#.Yc%)5<*Z(t *&lԟ*"IoiMS댲E#u}hiU:@b_3/C?ɞ0-o^ɂ#떺كϑe0v=b<[ lNW8:YkF@8ZVׄsu.5Vij^VL 2PU=₵H]]5p):̧]:Q='A$k=gmj]@(i|zwa[V j'yq-+"01ϣ[#0bEެ6sIz}|`^k>2vhOӣ4Izp{HPurh7':hRKRE$zhu}"B|{]kz{vq+&&DG@)@&jzIrH`O3s*7ִE NM!g)ROJ8$!հ\(J( JPqRU4Ñrш=d >w[ӛS݉0-_ `-5E[AE@՝goQ2BOdc1\֗JfT'(]LɚQ\qh5uzlg1ֲ*o v YY4.3[R$ G#P`\FnAذ6&މ—]-W3ԙ2H,{C=Bx@NG!QQm7ƸV?gYE8Y< A8!HbyIL\,v mubŠS%IJD|"#DF«FvT_l0j{f6ך]ȁ݈Ĵ<14-}?GTЩ7q(Ioڛ n†H_bݖCn* _n4alB5"K >n "F$s*U.jz%%n)@QZP^Pr>y=`^t2AAW)kEu6!t 'DK2s8+W$b=\BNP,qUČ5i/qm5r/ OO};et^׽+~n򵽦&r!b ,CFqS Ԯ\q#&N t8I9[ %p9or(Ͱ 'T@Oҹ+J qӍJkgo#ԶqqC!7˿2S)5/"u(WIX3(b vi.ƞfcEϷ ̰1lN(A=_ɣX.SD+ nE)B>.xN.qqWRލKL.?RpO7]rH\k>_8k-񭒥w<2L74'Zo85"lÄM"yNHe[OrKpֿ]KaْH;[nwVXwpzr2v8ܹi6q3.46OeD2 , `Z V*AJ- "Gn>&^dXlK RDg%Y;v$l;lIK'@\k$%-(*<AsܢPOzaǚ3U(@,l߭>0L%`ӀU|9vJ _~*t6׷Z*1k5 ^N%o[Aـ:F_(W r9% {D%Oexx\~% T La%C"07AڰUO xVvKxwKAp>F\t=d[[9:۰ sryLYH;n{MI"82/uPS_``|$?"em-9&r CVFx%vXrRg qf?zx A_;Syu')vDit=e%ftC Y.s>zBrŃ,PI$'=#{|jt4 mcQa{N_@OdT5 bM"6uR~mE<\Nch!}omP]~kzGnY5gO{$<+S[Λd qm|IJRWan(e4S[|7f`9FdH]&h3Ci腨;R} ɴvFP ?+?o7cQol }^qf\xfR*\dI[y zr=b5SFw<jx-eRtSS mF\r̫!W׺3[Z[R %V]6LuIXʼnu*E@]XNΥ-.zl5iָ > o%'b6 '1KF0wu_BQpEZB5:(#◴:8%\b|vz&U(BS MvlCR46NXfe߆y ]^Nu#%]v^ ͛ڵvr]܇\H^#a1TMF`gCdAEr;y|zڊ؂O'-VPfGF[ 9]JEo/w]2ͯD?:ƫ0ZFי] %.\4$9rCT0eC)0X{@韅кN6\gC=? l {mu*_?vBaE5~N0sNpdOS"[>_! Y- `p7<{6"Q ЕWK<`ŗ91q2^"zILBόw.7T@/ Юz'NEQᆚ)g>2BTdI5l }K L:*yl"UNw]vehtϟb_DR3XwI@#;$;t;%YnS\ˑFz{ QK/ԙRmȨ(;o8}IM05=^ڡ ~9λׄ'I+T6#nm0'(>7d8C_*h|4?{ H@P ^l V&<2=M#,g6~.b[$˷>|fzPFa]]r >'^Ad?T/Qĝ ]-&)QҐnO<k9՜񆈵(Ro* g9FX-*kj4Ug:P>q\;Ь P.XyCIW .fabd>$Mۑ3N6<0.ЙlDŽX'r/鰠)=+"yFÇNz1$ӝӎkh=zNl):+|)խc-Dd٧l)^Fj=Ӥ.%0rY]޸hgy\U䖩eSWP̖z͑;8R8Y\4w'ǙFѣs=Og-5}Rl>4#I4V"t(n`é+ΗcTڕHEtNjfH9%ERaԚ,l@̕ث|&~kBsoˎ a 33p5N'pţ; e>CnE4ErK3;j@<>Y(X\#j½,^#dG ;Vl_Q=›AwȌŕW &|?Hqnd d;&B1;IZ{h&|ߌ]NDY'Uc먢];gV`v۳:8xMH |:UKpN)s[UiR⣞q,9SspN%,AX~^ǯAkwp3 esulT{1*tˊp֬t߃tpt'd>`pVȚdkG*kPEQIMΕΆJhۋ9dqH/I?JTZW͇Gi]>IZy8Q ok&I@lL7΄mVyY1&KynۈTiYiLyKW] h% r/Pmъk(ϯ&4@缪փQ){ŋKO~z>X;&yxrU)vTA.CJF rXpOG.1:g(l 7dI@DgWU2F Dt6#*CI ܄UEV_= Y ǁ^D K@͑Y Rs`E!\Dp]D;"/5ov0uN! DIEeh_It6?±nI:UwG֎*b\=k3W9LC m)C**Cq,~9qd8ͤv /rj"gu :,?gg@$|`m #wXF|w$E}5t22u僜wZI_0@"Чn ?ݛŗ|h+06R[s$0$E]My_5?@SFpZiJb&3~of\A[D! 9" 6gxJS. =Ǜ6`tc^l>CHu?V957{WY}6<eV8#=鯬ף59暯Dca9,Nu0AAh|MryyW 8DßI7!'Ո˷^ e]^p 7=y@NFI&OaSi]h'Hd&snCR^!WƗ͡6Jlbhy.Yw]Jv %9mh{h3n!f@ooo<~jeue <:R#F-~*GeC'UA֛?.p{BxƟW(%U5o2'}Xum R͢ i;x6%2Holf|"P,QѤa2.!?uZjF ;)'V.䧮b0SigS9g?"m^0bdr?"nj6|ycT`1̛f.Hqɀ&雄K@7nlSql:7K^,ؐQ"`iMudג9}f(JT%^!'D@Br%rpI@w+d 9A7ΏgS8A)07yS7/}A?@? 1>T1t 2=osqb1yrW"B;FA*A3=6nzf ':rZk+OJWW`tE/{0ʰ%038c%R59.B~zJz??Ӌ?BEi"Wh bun HV+O3#/KzOhg(F)n.j#̩i hx6s22"rQf<@gJTI:Ö1{|g}XB(w01Ǿؤڎ8pevh$ͯuS9)=Ё?OoqQy۾Ӊ> :Nèt iXX(Ie?maPD[CS|Rl^U6yפ{&^b#})d$|0WU}Zg ;b͕P- ӳ쾰moo%;ew!HEē[, 50T_mP8ý,%# _$_:݇\d+CK5+y@-;]V1Joi+wt§2J8z?ͣ!#EE[˜}Y>#QXqrB~ Ϳ?Ɇq`TCV]lAy* nQ`|~+8y7mu-,4"gLŊ"sfd^+Yy%@HL޹GHK # +Xt^&V:OOJ]Mlo Lۣ S;0Wv~Iن= (&I|1a?EN78 ari j Ю{VJJ;5i6 &]D+ Z_6((>:J}C 薤 %lW2/gQrՆh`FZӀpIo3Wn6N&\?758=>_,5_&kԅg`S-=a9|8=긫ӿ9#I)β8}+#.XVU?ұlyEZ9 B=lOrxхjXb*1`}=J{B0*'LVYs"8q|Eͨm NשH%tu*}_¢TBBd6c${B,u3x$@n%,ו87YԖx)[S)5'GƟZo*Ե 8ŕ(L=M˖W噕tJ>V̉Nz5:&!$'O }&[Ȼv4M3K3KIہRCf |i֜ϻ^>ͨԞΐ. h{GNld݆ 2\CZ#n:@8 yQ`/-]9^:>og܌k@@JvOPV' {/ڳU IFG7$0L zUfqDw*_BB= z2Yk 'Ln(./xLB`ap\tf8/2ST-fi"}>gG iuocȆIpS*!/rH4|t ΢88!LFac^wM3V\#QWNO2hJg tn fT¢R $"JzN_M^TPN@>pNmT(-I&VsxEܓ?VC~`%9 ㌬#4sU#_D4,SzmK;lz'hWc(K E$2FD $*]t?X%ПzΗ;]$7ԸԸtgn[[NFߞΕ*0}g!|nǥFUAI% &gkF/}=O^)!uV&-Z~f۬;>a*0$F WՖ3oI/LodQ{X{M>j(8$}Q _, 9ež#dΎ60#AQڐ^Yy. @VAo@y'z_UhVKJ7]^eMcZNŚh,|~Z13n/(9̲}GV Ԁ\2*Iv$a% /b"XSYfichA)l) ? JoQ<m E4k^% vK hvR>W~fnN \/iPao[ E[k uў]1\#/E/5.NAhR'ad))Rۤ)x`܍-E~F˱g"տ&*AX>HMz 帲UXKx}$̲*+2ۄ >h R 6bxRcehmRV8]. wØ)vo Gs/n/S \gȊc0(nywTp|$*&4h-j"b c|vvwÊZQ`+ M!y3qs r[-NhԨ[:w$GUq^A 8Ѭ8dB Pٲ XYTOؓkk{0 JϥB~Ѫ8p;|e_j0 C3(1(oR`eQm#dϫLSSPK(㳛H2by3Xm5M`*9Vq^edWmaEނT٨A˘a_@7NBTdcx^ȠhKWb/L!u\AҮNZ :|VH a^ȳCw'D]gʺs)b`']~R.,/SifAp` ]D)rAj"WWz ^:q-l};\23,+.>I?gە/Sʍ=%YDm)c>S=jĉ~f>|гOE(ϋyWqS@* `9 nd*{b8{4&MN`R4IJTjkMZU99 PXrGEx*2nytY]KQJ&g H$6M55 9ɤ~6R-5o3k>r[ i}jN=\ĥ-wjET\14f7ozi0ZPО;{ [\hM,,{"GaN7HڅuU o6{Z2of52g`’d!fI2>&ca4L%@1_w.%4MUDKƸ_SXMTi.@R2;妁طWwSK# _RD䎜="ʪ芐?( nDB!#:~!=,EWa%kϰKD/By;NUmGu͡yPoTjT3hyTмs{8 RDwJVǦ y>'51!UA_2X'/pDbZC'n(? rFfJ&y`lF^HS}#9x O,:=Pgq-\k6kCnP"xS~aU-t#4 >ݚ$cݓ)O&MϽҀC=̢ 0c+W|c */opfg㹅vIă 51)}֚⼮H) p0A+I]4^)h]@Ngͺ[8BH V@G樳BA/?\K}3dDbKuqf~n} ser/pfem/μXTGVӄH]ACdXeQ%:7)=О\u4#SQB*e'7uz<]4'o0J^wU YʘTW϶%=ZxCY O%3kHIvy.y.a_7i"IyUz. +HCKL2PhBSञtGꉌlOsJspU9$e\mJBVPsΗsT3>"Xrǚum}:n%C=YΟ>s2{zMm14* PxI|/^ 8}y˂5p]BrG X`J=|DpY$BeAV6+?E(=`a F=+^[ MBc;ǭ wKX.dwkb7?enu w0hWXMT!`4v@$9 ф' \<BVH"Qj8NtU| 8gS S∳P 8K& %NÇQ-A=bu^WRy?*gj_׽]u԰ژ*t61$]/G;O7LvEļo?v //"mys/\pWz;Ұ >=HFMk]P00M =Z5 jګэA<0A|O=d0gjvE~)!xX[K?r\]:tb'[@Kt3<{f9:? iMp 6$a^U4dH/^]v"' "  ]3ueT,NG~ a02I<9L¶:׳-%e<pƫq~5%k}Рx:,M14?N`kS|g3}ɫՉK_zeߨr[J=!p\QUF\!_>c*NAꭩ v WKkP#NT`>}Tj/\]EqWdJ !Ql͓ YFl@l2PXy~E*k庿/_z$8A46@99Cw^N}t{8+=v˱:rg2#*J'?-⥢: <N/⁛ g:Pqq:K! tVڊLz2Ts[=r)]]-d !ڗCczUG?d )tc1H]CiqX[FYϦ0&QQ_G&9qTӸytI\X_jz|S7LWN;0 wԑO^85X7wʵy)Q. #6]s\N-j5Qym~~)h/qd'QJaꃘ},u#7 ͑l:;6Qz\MWKqU:2k7өr<锶Ԉ14#=Xö^f7ʩaCE_0Co]DqgxgFbpPW(@PC/E_U:ƢnX6H.R|1ʕ4$kFGWB   ޙ_vu~|w%G92~-G殼`n/zX0Mn7XYi>]P9#Aʿw B]_Ғn5˂ڂMb"}ύOQv86tzDm)ɔeo7ߣnq}0d+?_v ~P\?^R OB Sc?y2T^ٯkYdur5%gu+*w:H:=tHv ڢج{wfk\/z;"Sg/dfpbcZ^q Tjlޘ}lڔ.v@F{OHBeGEO#btLsFn; w}s$6D,9~ w['z-DĻ:fɶdcT3;%}p>6e tnSi"O쫪Aw|"dr7 "B@˞h!q.TK?D+Z&B Tgk:lxWrq`yxQjW(G=Mg+ &069z+Yv[EY,uW2SŚ)#с& (_+m\FE^ ~ |w'[Gn*I[e}f17Ru~kd92>C31h"~-KZP˚),*&&X!}1 l1$8l{ L{S^5^XfL:HB:JODĚtdıH vQQ":N,N DNRW"0rZ۠70NM׭\K.#i$p%"PD+cxXxyKCDĨkODl>׉ko58 H6S~_- &XJ!Խiv!G|isID= F^ ir=yvlgMTMJR`?dg!՝Ȫ^F{/f#9U;[&dҽ9OOF_`sTwW0 o2n+V6]/1ƛ2,6 5D|J`@ vȃ TFB^&ITʤaq]G_68jwײ6d7MҲn;?RN; xdBӲs.3c p)/SizhCIlh(+7-ӂ(sXRz$Ɠո r׊H՗D MIs_.~^ʟ<`J,顼^<@wo)U}øLR'rUZeT#="gS g\6=)uË8gcČݘ p_dY1 -D}5jh9ؑ#;Fv~þYZ9!ʮɽކgrJw3[j]O2q?IgcETa ;`ޛpGecH[W)?. ;ɬE2/ROC$nv9 ٩: x0[AcDI:EOQ4QR{?_Ho{>x%6I޺ǕS騪-msS`W\+E0R\|KDi\L DvpNDTsdZclyz()}MǮЮ]X̚jr,1UI==ݜhvN:9E-50JUY<ˆ(9 g'qÒ9#ĢiNGەs4Ŏ~[@[x\zW2VVj7x\RϟJb~jF.%Qł%%jYqW[  ?}|>+Vl 18UckTbn`N\fFߛIaA@Ei^^ 7H1yph4HpODʃaNuG`ai0JkP ^W'a֝vr|($pZ؂, oN󉽃c`cM ;/> ofQ<( WՄ꣣bN:$:ƬiLq+3USԣϿ.u1&q81̧kfï&#] EOoy?=teCQs%߮^ xt|9-RzKðn v  o* `-[m[f3H0+Pc ɒfMxArtWS>=(ծ{q\laK0CM^y_]k[2bIg;&}J(e5^+{KGg g閉тVPb RjKbsV#B51hp%gDDC1Ԗ#fuDymW8b 82NW[{/mz>2 L=4FIl#s%CޞjO0hp8}7S4j8~eN| O;SC̟-ЍT$4F~f9ºotPenE(">>y)|c c%/^U BW52L=Ha|G\B8-e+uS2٪W"oV8)~2fT* ɵegyZ̽EVDVe@Miڵ*ж35H0նBޙmj MQm%}4NR`fj Sxp0+%K÷wpn {:ؤ2 wc5 ښ|gFdwJOL{ڤRٽhSՃ>ǐS\]bUM[Ub<Y1j 0Jd͙B͈QH/xO_m[TN3K7S֋ a犋 0̌h % خouQ\6EH//O*pr"_6puH6%kta!1̄ŒW^BqhmI6 n.kÑmFECȵ *^N>Xhjx %.CPýaAq {ɑElf K -u' r6[z=hdu_s+C#{ mN5$;fk![6}6mkoy薃BU9.Yyx{* {8|ځM"C d MdRlߩ,Us3>Xׁe&'?tX39u:A 5k\>œ"oԱժ{pV(lbu7֗N<8{tjk vIH`#Gs<ٲβʊuگCV,iL:j4:I0Z$dXaAM<~\bDm`B &;D顁s5;H,%KdC _d.i>*F4&LNUӧ5udqq/;Sm-AS%wH;в JzxNnPЯAͶWpupqh(04RTcUroFOMGF >et-;>QgkAa~-~ͱaeBc{!#4G.JG<Ibm{ g#ЬJ`D'PP0 >g2i4~z6¡t|s̋%ޮertp,,VTGcK\TlLcVs%2aokZ*@V F%1TXIܣW oEWL3eY˂>I;+o*-yaRʫZX5R/2ӜG-Ur01<5A>;8u\Vf7]qÄk)a{Qw$GDYQBHlՐtO-/ UQP AiwXκK#9`Y!T2 y3ү[> ,[+p$)=ֿhl77 {9F1[%tF_9'bڪLrQw&zm{qW}iJg{}cLMAڭ`hҗg0ͱ߄pm"y?pWԹJu)5 >!kvr#*g_A!l$5my(V#@ 3eJ -o4.8 %uu% *c6D_Qboxp]]@0AT s͛2,fzj^a :¯<6w-:_ P1Ug8{;"mw޻~mV:ŰN}'坓1(@H b w9QG(N' ^*:Z+mThE$&jomaitnOʉP*iJhO㼸[|7" ]m'* Bђ|4@?QĻ8̍P!2^i<6*cU (ߛa2I/OO]c}\&H(t=ћϕp=! 'cǔH2,0MT]BT쥣[\cYX9p*wM0t=u=gWL%t^bBsMLCpp@8UWL {4;|Cs r1?_qOo51I7ťVqZNl1w;(t o'<\D e%+hG$ph?ӿpR G<Ǵzmfe+.6#TǏ4* lҼ%LeȔb^¼вڛr/N/~dc -8aۊpD[= \P "m7}SfTۼ%?X@jbc%'$Mt'hf`kĢgAJ/:IJqUF-7}}2b(bHa\ yJF9<6a8.T($i M *fxe9ӏٝE ȄFx6ۢZ[.O_ݾM4v<8{cz]4P܏Næ<@ytn0L[.yJ5Ukb$5a jYIWc#DRH7Ի .W+ vxWsuk9ʃ] >;DZnN'ZEꜺUղܹߖr 4JmMr:Lwi+#y 4WT;fҐGHQ]5a؞\G㇬"\gkuUֆA&׎^㹄Hw 0IoC}.;K#iTM؞X@w{^z/C.'gQĐXK/}`!Zޢ5K{REl]}?V 2F|b/e`ǵf4#CĈE'Qg~ zv:sd++ӟ]-Q?D*9jn=,IM7]1U7DC̢ {b((GԤ]ǕHW4J" `ab-9l`mտZzA23{J~Z:Cj2gaDwcW P/54Yeu4UՄ:) e%J?C$<ҧ!ʈ/: AQkN)^5),.hILc,[ަ|k9#応ķ - :{yo|^g] ש< %rfJ%Ԉu.ΗU{שCټsXCS԰8[jvfg{xj#Xe{ѭ~5vJ'pS"'-d$BXa#̟v2 ҽ@N,n1D}tbJ;D]i/Fi14Ng]30w$>r&CF.) Qv4w BQLr5 rd:#D;ide1\if (Fh\Lg4^HAN󋗲9x94dWʣFtTax~wJӑ͑YŃ6uDΨ \q!2 hZ=fSt5O¨ǸXF{ 76IsPB{ujU".<yHJml B+T//Aęk'r&Lhq}C6.x˻2ݡBg4G%dZed:L)3>Vä-?0sR#з˂ 6忓%h5d"MO¹U&06 E2MLV()ZF$20?d՗<M7uي{!{xWD6cWgou}8 H.J"uB*a beyٵtZᷯ_ Fz_kx;|_x^ғ>-roȨhv18etIuͤehBˣU}J혠t3Př˗Kxo{"mO˦h"\I2} @ceJ"vu@RM:PQmɥ Fb?Eki0(C+T4U5Ţlz+nq1/aEURGB(FGB"mNũڊ=N};w٤ I~!HB4bg^HC˨>>m}M㏦܀֩)֯ŻǻAr/7Ҏ:M1enFЈ{EG`ŧM*j'R]:pq/Rcw/P{)/D gx6A]s rAG/j #ϼMcfxCfK?3Pɑ&k\!I%ͥ1y<-7x$<[:tPi^$;Eju-MTx{\eh_|9!aʴ@ \͑g0|y@翫pGC.5~PM{;1i ~. ] :@0G-& r`M,_K8a٪Q1ϙ\$%={o' yԟ,- sOOt^K ?':_YyΖPKeh_P{Q#H' ,P'#)#]X{F_kye@ksW9P C#$Gߐ…wS.07цG!4,|؎o$|)^l8#İIX^ͳ#sT{DȆgWmv}g%4xe3 O/e@ٴB~| XG)fQRgbNGC& hL PQE Kӌx i(iq?J6ȗ6K~IjiXp1@D1@m-廎3D&Zxbo[ڗ0 '8,:oGwmɔnR~iJѶmwkmJ90zrȶbiH[hGZY i)c5iO}eMYQ$#&#XNO<S@$eǀ;njzݑs%%T0Џ7A1()o_5DC5r+ps£K|E*3][{m+QP>sɛvޗc > #N". hiĻ6t1EY\R& = ;N"dgd>AG'BJze;%i2}wiP>э"94&Y\IL!=Ddʫ*7Y%qsǯCoBnxft哳ޘw_[ַP;WIo+$|]˦$bcx5.Z pq` *. ,jem!ق8}pmގAW΍FW&0 tAe)l'#Y-hHy0q0>QLMJ>E FSb}ѭ]yEP`̉I {;^[4JL~T-OIlaė-XݮS E\dž#0,0OƚM*YʭUTQGF A?O#Ws85M6]9Q!uPt>҃: W7dNa0o?yJ)^!'VqU\!ӌ,6mŒZ h=k_g96E/Vs *=-E/֬h۲\'>U7K7IEؘ]JJWNSӹIq7ub: |H꾢'O)jw8hHLH{ K [+Ce?'6FEC"m3+VaCe6P؜j&Uq]F]jt13[ҵI/$J{{A]!7{Ug*] F޲,Wnc5pSsg4p XQo=5X>{wS-QG%Epg``(oh]%䑉oYUYcM,Uc&)÷uget@fYE#oPX1|^T+j Kdxf0ֱdylY ᄵ`mw6%Lܖ_PC+6)I y`o!s)'.4n?a==+AuKu>a:nmk*iD%o^f Db!u33 ۏ9͘믞;6?oMO2F<9_F;t"iF}|/~V&!3HQlpwafgOM vt;Z%B;ib <POZ_- jGV`lΗj k'LYAlB?bЪP9Cy.px #'- N$ aEnG,x⡄7'Xc=k3_,DuscqF晄84M d& y<$ؒ:( >৥@dxBuG;N}(3Sy(E;ǁݑ=}SH)ȫ`xv$N isw$b nMy4Y/kaBl8uER&0ʸXl ]v>ʔ"q&:.Rs6W]N'B‡qjiDYEm<'wrވc DwUdjmM{K*o]Xtp[H4h }{?(RĒfg}I۽oNeܱٛr<S[vg ojeϔC:Օw *)w:qu@zb2$+[ 37؍˘T_P~-0R#cpr٤/'eqP@~aW!?ﺑ9jogdMuw"hEU͹?oM.o(nDitf_ZIQ ?{v/a4),%l(cAX)&9Ǥr]20N3SgAu>~9[3s*@{:6̤0px„Uz~p6f"kc$sY̿3W"QK;})8OQq Gh.R}!3`2P?ǫǀz9 X}/lȓ rYj=jâl#9-}EN:m X- R ,(y@42NS9'6}HQ]K^3MXzyXzr:=W}רvwpxRG_Ӻu-,UnivG6.J@S/΃6]ߴs$2%ol15MoO#V`Q(Q[tu::RZy[^1n=!H^OX7ۛy3[ϊɥW? ޿ E %Oalj%sI@ŗl%&2Pd01;fvzX:?x~Tֵ^fa9WudsO X YWb vV =W!/}}}KVlP.чGT˚-ώ(" ̲T$o.B={kGQWqn>pЌuLgc#¶8 rqTѯ8xu^/$M Ď`8a9!`!I\'81Ӝ<ӯxw!nǬ\%3u2A\"H#DJgRNJ}~^.|Nח>juN.^5gq[%S#ÊY=ZTi;2YE~^tO1b˖Һ98{E:>*TuX`9/aKGSj!sVȼ+w/7UAwD,e 7>D_f,mc,VɅӤpu%õ_Brf0DGE<[ חp6׵;LTΔznתK@y}Lnw' z{`ĉuU_h<lDb9+=>"(6&ڣo8O!j -KvԒbVszFNL;yA2 FTPZI2^C.GΚPs>Wff-z2Z7ҙ~Q#T!aA\0 J\в王7jaz!@v6 4vBuW,Ysj Y|@}LR:Wu%c׿N,k,9ؙI&sfsF i&-7U-і}-ؾ'dyV%'TB:*ի9* ň޲#^Bg",YbmIxI%#{=r [#i.Ay,FmtJ|c\n3?)$mb r2dU;Z3.PNJ;YHM5;C(8Kwb N,[Zs4S"$Đ>`(% uj+%Yzw92tΛ|F.?&Q|I7>?*fư4bc @316/[҇/j;wܯW]M~t?m?S5#UF<\6[ǛoY5^;QݛF"ؒ6dH! A$a(3JEn?|FIJWL^}݂*Вpwv 7bm> &z[k v f$дՋ@>s+`aϞtҚ~Q9︸IJFh6sA;\Փ,s1[oX0~FV\nj)7{WymK4  N o\K#Co㇃P^roQt~3S{f6cet,j 8; o+헀cA7$ɠ%lߘ怽+T62[qVi x owd*zph_|BVpE1UFC.f% WlOzSTjN3*B ڢvr 2! !' XNR%x`ߌRj|!.xDp&GV#bd׉_>3{s n6N|ɢٿ `ZTM|f'س6~LzT Uw}$P&}gC&x-`gϭFYՊX39<ΆI=/P_[(N%s'<[׀+`T!HvP/륏L~i>G[XdMdvP}w3GC&:CŨr!CbQچpzv4.ws:fɉWD4L':  <̑1v* R#K1t/MĕÏˁhr%`z` ҿ^t[~ KsX#~[~jC(RҀ*چoX\1T&`\mT׼fS{N-A!;E:sW&/{gF}߆h,[:;d`/\W##_D&g.T dIq}a?S`0]Yt ӋG"WOă(ϮdF$r2Yo~~`Mbͫ\_\"R8^'V.͉ex&R3mtua[ȿZ:0llcl,^AT o- d @wHEPF } @MkԺ1149_̹2GEI{;[wD=o [L4ޢm%^B)]S9fV{*KʿP˝,cnj$$P{3 hB8DTmi+? ,B#?EżEߕ4iEW$~"ol{Cҷ*cW?Գ$ϊu% G?Zs }MVRtzzܠlUXW![lFޖN0StRY`{_ee0ET;#} Wb\RQ*a\m4iT&m"XI**bd1bGcǯX!!PnEnA?c! Pjl`qƸƢ;/dN 0jU~ @q.=-↢V6? Ǧ(2aÅҍ1> ?;s'{ Tq w2Hgǘےƒi$rut˯ "_Sb:& >T${a mdwx 3eE=ބi2ooa~p ug5B< pkR )k' ,G#&-7,SDBzcןZYI'vL} C|M9hK <.WFLԝf=ڜL,Y$j\ateLX$= F  ^AxFTviI}Oɉ- B.|0\m[Z~/bn6P hxk- sБQz*&C~EUK༲xըv i+z T^l8%u; dx.?#3L˒i;?p2)~Crvb@}Bv Otʯ4/{.7m?l0NphEUCL PxTdJUPu V|Vƒ:DY KvZW~gfk 4'AO<.(ie+&sRLi ;9 06>d|N"Җع@;gDv>Yد)Zъ8R~LR!naEjRɷ/6,tV0rծMnFUWx#] (3jF/LnŜ%9MAMqĬnh[_bz&Er5`|@ߪ E@%0E!B Eqdn;P F>M~]FbCjZ` h\2MMsNv1fp|wa>1@8aLI:v&ִ/b%Bu}3*8;b%]FQU ?LKΨ ؓ!T I]."h qЋl?GQ5WX^(nZYawi3aw}N&/7 MβMt ́oyɸq5 /h'\&o Oy:*@@ȕ5S^yL,鯩otN?M#+ pwcξdfn> s(_ xl^9 Vvt*AАJL od)ov*NQ m& _A}oօHc'"_ *`ss`SGx#ޛ*b0xMp8$@1!Rġ`%9#e*Z 1,#^6ǁ[֑*9?vٍ^k)eKr&ګ^/UQN{Y6*q_ͤMR(`{'DAB/ +-wR 阭&ZuVRWOSk!z7U҃i\O4{ eTǦZP@O˱n7#kL9jꊍ\\q4*;9޳m9nrPc Wڷ4HPX5&*3nV{Rg[*%Axôżvƃ+;jMε_smu=lt$Do;vabbƢ&C7`{0r[yEa_L*A8VFJ iC3ے{m(]\`}Q-B6'у]MBi,F^ΧB 82wiqݩ?E :$ S5zJ3Lԩ_ng*z3$^2[f <3 F[>Rd~28T-J \XwtYWmao9s0)RJSܰ'wc?Bf"h 8XH%Ąc;s9I8>7c z1'3s]yIb vkn&l%9auL.}J en#0OН%=$&N@ߧU8ш/䗤-Fm -waeӏ}\dF-$qmlp[Z&2'qzc1X@L Xd j訉@h#IB'߶8,P+|R.bZ6MAW, ) 83q-{-珈c3m9NTcT^u׌ Mhq/kt~B%$)abA`⥏ 7_KԗS6]>%$8V@lќXl0 ٨]Ygs~Ya`D1iugP ?cZ]˹xo b-,G-HЗQeVb9*4:݌&g vZJ+VֱKfCHޝ>틻icĽܙr ܢ[Q찉 {A s_N9#.%f5qŚ+:w,-q:|徤 |n X)2Fqtq&F尚k x:{ohĂ& N>V/ʉZ_M_\Ќ"ϧbMvDC<"^ax }9L (S*.<1Ϳw(1%A+ ~V6q:J@ ^?:9+ZY!\F!?Gn0XmQ_TIqbfPC'aP)t֦ハ9^c l[ܴ h()}GuN5tF0Xuu!-XBOF<9b#*`19y1eV5LBם{"x`e?ͱٽY0b6ebuHg\kj~P5NhꇍBx(Uj $X;h@5* f4 XP mb&`2?ͥqRv-y*@!p ɓC/a -"lJa(Bf"PW>F-޷x c\Wfm&&H0&º6l%XQ2h߾|֟^״^(_I1C|0`/-.b,w$ƪ'l!N`roYYe*v /B 'w{{u#ȃPs K7̯>%ˮ"ë$0e-cs~ #Y-axPLdǞo$u4ndiI5;$pY@.ĭ&\DK"+ndd^bk P]a~*5ejX:Y:J9?*"?/y,uVo {VZđvh]%Hnp9/Xʨ) S#[|vڦZ)sEMv0Bs\k? ,Nusо41 LeJ")f3)Ai@a@@`&:Rzi85wY+VF,M5s u̖[uOܔ)ըYk㈽20Ƭ#3#-9D=k n)71/4<`WUbuԓL$CEq΀R`` Xf?T| )*m^F7Ӹ+В&*xƈY6]r, 9A|R䂅hE6&\!8я}Kw̙_cHC`͉λg %b$%^pzU Z#hͱf~[7] :@GB|\g (,٩ 0 {dֶ[?`>NN`Y_%nȯ$ Ơ3CPkb1fvaȀIk΀zc1yĶ#B:B- ΤlJp&QװDMjNvod[\$WwJ \F,˧r `#@:LJ++!jN2.g3w ;ʓʲXj^cx?c}aBw 8LQT,=|:u̬cR✡ߎqFc-i+ DQȿv)/p|C'-oCGÆ?{ j tڵ'`׸t!}1<~Cl+H!Wa"uUd[kҋPUgeD-Fn)5%m\j$,#ڋ6yuUH[=8r @<1-.|@)>FBgĝbiϹ,!G A9j*pʥhTuE4JnT/:y'_-Ƌu?o&ƾwvn/h_A61-,P'MgwJʁ(IW'# [O:;)U;%w =gZ\PI] Q! `R;;v &"{w]f1w&C'"v@ZQ|V9Yn}ɍ,rV\i_r\l,x *]άj޿uLŗMW]8*X?[T krt},+)1dYS[#a.f:ާD! 4AIbQIn%K8]3c7K['}B}93 ctm#iyqa(RvK~{c,S8I2+H}3j?@7kwjebq /'t烝;vdO`kq%Ybobp uLI2Z]SM4GpO1O'.і#H d9x;siE CQcw?0iNt!fuZf;gl0as5)h_3q<8Pܽ-'Gn#UydBҺmo"r[d1#P1`'4@s\!|Ո |y-gwDOKN'*G֋Htht4*]yDp% g⛟+ϻiЌ ̓  4SЎ_!MoI׮JBP-{azMlYkq^B5-q7}TC71Lْ<%ݚN`7!8y֏%UƤTU9^GJ&bsPP1'W. f&ey,GH""M Y23ֹ$($\}z| iVUh bOA8,% _JbG 93`_UY5?Ȓi;Sm,,/>7[k8{0>xW\UQ|NxR$\"0ˮ sYwgҀ&uGRa8h9/7?vYSLRFw*u''v"8m~t)g?]ƥ1CQbClP'a#0EX>$sTy瓬=7΍ =ⱕśv&hgy{$ʺx/Y(19^rs 6_(#:g90:ȿ+(Ý"++"Sc GV<[n v 9,0>d#=dIawk}ݫl6z,DC|ܤΠy# ɹFqJxP|)P^ol &$ Kpݖ&3t;?ĸ`B&}L7gb:O1̡^'K{8 ؤ~EaʉjeJvg戥b :0_Y~mǣj (=h=4ZD ɂ9dR`y M 5H$8z֒4}Wb<*o^:<( gP}v*%"0pxڧnG@`Z"9DtbyF_Q!t9X|b^qt.RAײqz^dζ[Ŷ=X5%IyzQ4mI&2Qbl]~~AWSy-B32Dt ʯ!S^ Qہ[jGgU+ksF+k.߾7^1܁Hmզ a6pcJP7undrx-l}&{trC?Er}CU; rml r[4Wtjo=%~X&OXD0?-t m[+9uaO]_&c{T;˜m%VAER9\/_c+ (K-w7FO&c)7VXgy/9.w T02wEq}Nl+&+2Ĩx1cku-K 0h-ojHSHsO0 WAk_{ FzGI0s ^6O5W:JmO;?"f>W}]S?jyY"8F)ޔxNnٌV@`5L%C2r_50T^HC~ &>/g̹笊0mùƬߨD 'E2m\䫆\%T# yF:2)2II>S*Ypn3O'bBbW+pZJ35R 'w˓nq9bnر-~2/, LNA|-9ni$DRQul l:3?o{]𝥔$?nOoEeK6g0YU$FbG/ifwr(tzʐ$01&ҨsQPryR>7=:hOd}'e5 H?cq=s2^w u-åK>?gqnc4(c`?D쪛xD 4/dΥ&';Z_iQa$e8Юi\n惣^t>GÇ,;7_RP)aj'BLn !PEbOw$7{,$K?RsTaC.1sYjI#%E 5yTGU_d-hD\-hٹȽȎjK\Adt35Ud /z{J>Cw]6Sa(]npV;KL(FKVRT(pm`^e˕^/N!qiLQuk=P -ss$JdWC^,1yMHm4KIj+_~L(@dCane*^K2)aNA`g+\{œ|㶢ڪS*ax;U#*Q#?5 :5KdQEFmEft9FgD-z<1c #0-IM[MMoSMZl:zcp'1 Qz(¯}듩7@ i'Wj^D JySwLmippV%~ŏM؉i}He'm^7܏'Juƨ(&iht~?QdSLr$QCRdnV߳(#Bk.`;"`!HC[4PF\)/) 0bIܓ"ffGtӴ9a0BRTY#$G~TZҧڬX12Q{>mK<:¢[ Qo5k^Sq./y;=!J;5s2j:J\ ʎ";;5o*^MCXd> !йn:Tu(%+Xj\f{5rqHQW=gYH XWqe$b B53[OR&ф6u2#:p)Cלb[6SV8s-}tƾ3PǸ^ _Of}f=H3j/|^J0ȑKY)f}s]w6 07Z^ oG-V 7>?BYU8%=.[|]X]pY:6[Fn4lFʳ*5~-)6UTgf8RƲ*i`r[6.x3X9̑bRs+F.ed3J?gwcnw\Mxb<,CCZ6Qw&h_D S?O=CEGXћiBf , $)Jv`XK&fR_aUg1wm2E"(c+R;na'[\K.d=1OjY,/LZV0"ArAbm?{IsK.?PtBSKf9sP\1zCN k0ܤkYYӂo76cr^WYȱpʢa3hcb+,b-Dx@-I`<ٍ<'dr}S,WM@ׅO͊RGlKs87/2ih["xtTM =Zd"1DLˉDdY\Ja'&w0%\Aly3Őv ?|y ik ~:idL:@%^#zArJPi.Ymt"ˎtaReC8+IAGъ7M> {_t$s1hEܼ5}XҒ~tهZY :1୾HC젨*Wh< =:G+ ڊORL25n yDʎyu,՜i; 7fhD.-D#P㚱Gl/L˱zscB`DΝQ(M%..۸uP&lgUkVɷJ'}*^qB-^]ڵؙ8JR>@-^_KӒAEew-w$4xL,P[.bXeAuVFQs1t:D 4W;P 8IɊۓ`@7ঃ,p4nlo@|Z#oCV\͌hמ{@`.~tڨ(q_=–p0g̼"7%;*,0 ClE͝IdaHO׶Y8?.ԑ*$x|c SD*Bs6?zABš 5urGy-PUhQL{z&eE$*Шy+ W F}[Hy>(g537`5XP(%W^HwzFpMpJ=.׾~sq\vP+lBMIbdp^sף!IruhsēIz_^T0eTgm> < PºY>9d߳Ӿ$.y8b sA|{EgAEzuO!ݵ,\pi|] DJh;0iѩ@dž s~2"q@pt¸mLJ*Șᖣa-oN}pLDOsX|wGFR'ժ^2{L34=w8wCsWZ9y ɩ)plPWYxT3KZ}%YaaKnއ'^S}߉İ=0߮P,A?N`$U\F8bQ}}*'mru5A"y}Y0 ]N`|Rh\T T^ef@JAiΙYjyh=A#ܢDŽd~j*&kD%:u94b2;T~И\=,\+>6FAt;^cE`[qg(Ŀg1Hp{` d>\[ haAm9Hp8'ѼBj1y1Sn~̜WbnlkKsGUn*]*sb^]f@0QXj+"DNvgBg`cOμ6XB;3l_ 4ywKG@C5!t#},p 둼O3= ɽ3 ʁƜI>Fk19廳JqׯW}? JA_xFo4w2G C7c+S`m@xd<ίՠˑBN"HT<;DQ"k_ X?ٙy'!QTSF_gk?ٽTƱ=9Ei¯\,UtZ:]zNXd0IL%'r]8M 98LVUhAHc)>*20PNѕ~.;`.h|N]YVR2kxf02~6k사oZY8B<:|`Ap!cP EPȪY}nxғQQ3yYklE4$S~,D|X'5&%V[̀7k{sMi6R /{!!j^`_0CR]d !Ŗ*aMi= ZO7^w[U|- uOakħf"V;0>*3p}ymF%VeeNX9ujo}oWPVHY͞HOZL^BDU U%,"{90l3@?6<۱ bfzgM2Q!LlНLӖ.%ंjs+VϯaDj"Tu1p&YM, xd]HQ[w9X RGo}Ή4Q&:OWT< |HB+$evNIJPs! D4+}-6ck.d{E)޶)rkRFΉ(`\!b,-r7BIA,io.o|0| Q֪a{\W; tܤHJ4Zrd3ɵY^|T:JP6/+ٴBA¹eԃٯ"9P(5gLre iL(ݡ yXԻW:-%Cb\ W0J,Qr[%ߔZb 8j=:9)΂՛cU8旗;WXN18RF|Ε|)L]%1 ΈYO Vn\v6s҈D(L#wz5@]#7V\?1ӱޯ >OH} |0K:Tnf0̯ 6 . {?9OTj_F7rѯT[s&4$7\V-hGP&| NRe`Zau.lgKpx@Rfյޕ)paوS|h}X;l5lhE+lj)1ru?6bt>ݖ,qG3XШZAȟ0ץ#"ދ_qE^9Zt^_R뙻P/rGj>Q~ vd ] uMq @9ss7A%s6|N_N,jЈC͕3Ws*&&< 8~P )MgC4x5ZOCV)Q.pVqgoPy՗^e|&}Jؾb=|5sYiZ /2@nDe#+ .n; ^@<䏧'sS+RE)Έ]x 6z@qbd,zuiz5 Dqe.;st~ x6u&tԥm;~G2Սt>V%?mY1*o]3aIFξ7Qux4XD,n ^Iۖ̄wZ_MYZ>u#ntTG m52 Z)i$dY1}?=}>&/-%^ )F+A|VROpI+06ؕhS an*X1FT|Ɗ_L2;هcklF#=Ѩ:u+5'3gV BҽX@l$xr=Lj- #<"(|~YX"3G;&* 4▨dib/‡S5X<:'p7/ CUGαЇI0mm2ktxyc z7MͿU} ! }8VON'GNHkEk}@:s0X /5-7`(Rrz:\IOC%C/>N|AȊeZ-GgëBvTKn* PdT}_Uq]:mVؐۼ.c]=ubyψd:" m22a(cf^J̎Y=zrxzX< $1 Bc vŽIP "(꺔iIE K;8K?ʝygnsͭG@ 1&C>wr@` qD[@>Y\lBfs!2{^KNDԩ3 ߬ 1]]$H eo9V/3 J% yh~8%@Gy4,)_rRnWo!572'4+RT:\|mIpHj᫤sU8\vC6훀z3cLZdYo1Ɛ0>2>+yx45E>`e7ɒVbAIB ZL Yf-αpPɹ4UG壠LW^ys eS^>-Bb "lf,l4v`[_w O9܋EIFcR<ZY~ ħlSc?8:o=NN?閶_¶ƛbI=- QR5sF$ 48k/6*]ebZXJR'hÊ4<V*l],x-O5dSp6,- XFĪn>S1Bo#Xd}-lte}sk6FPATjg-T[G;ñH;-HJeqMc03=[al(zHiW|"N}!3z΅}c,PIƛU쒂$`XB̅ No]{%.뵲f?St\;WÑBH|Ό:,1H|3Au~% SjRqL%|a _f/"֩H}?)-r=У9` PQV5|jx%NX(4= /g kGG&\pRRZs4a{cUu넣^#cJړZ5ʫӸ Ϥ.Bԥc$O 6g`( S՚@6jbl D1;.s ZbUR=!herX|}Q6\ n Ge$ GfdNDK2ꦚ `veӤ׿2 '.c#Ai/;COOnXQx4 $PZѲu=MJAV;#@n]բY )UcdRÁa~rX(R .SԿւ:9k g[MՖK۷/\gHyY{m;??EE'qh`YAxiu&yt /N* [Qwޣd[ Y&(|QM/W,#}CHbO8sRL 2Z%Lp\ߌRWqLoa4ob'Q7ZalBRҀi-b2fEe4$ Od7Is{9&ގG9hn y(Q`ڔV3r.$rw,6U {Go;-Y {uɬxMNmǺ$1XоftUߞ`c!jv=(Zudl."1L |ŃT3_/l ΂ Ɔu(&M,-ԎĨS9e#ԵIɅ&{:ܖ-uoH[`&pa-F]E9% z¥1j^ݕ$Wg$Γ>tLe_LU o7ԇK-ʷ=vt=ҐMWq sI(R 3Mh Lț=7=uFUal8R .VH Q$iBs#r%~:J7e1 >q;{MŶ%)Qq7N:a ޗmmFsHh_ldr ^,{Rc &ǻMZf<2 o cyQƮES"Ka33bzl%D%9U'ߜH@UwT z8c0ȶ*׋s:NJk}տs>o7"NӒ2Q xqL^L(# qʍD&.fz$P N4`}#ؽXM%#G)I1" v rh2ťP9CWf%` l ˫5Rg-3^0dF`,2{iN`sWQ$#;낉_ͩt,Ϳ鬐E>ѰnW>=$6oqpIdL\kjqHqKU=_(~pq..#Pne{܀n_5 p,\8 F=-{ˡ^(.ё|Lz@pWS-5ʖwfjTǚTG1Q܋Qo Rq̉ ~Φ^+}<D1+)YK\\u+JLgl^zw:)`hMGE_Yl~nHy$W˟$)bbL)ĕ%-lT+%AN D:-?v[Cg„?b{Q9(\ |ah8&Mk٦*d/)#w$1菥\˧=lPb GRYQhc@ 1]=s|"BSG37!HZ<\05`Z ЀޕܬB=)-[PEŷx]P+~DY|3-w} {g-x!X/u}m;񰦈vWi +mbo{f(?puz:d:B0W">2agT*8RjOkأѓ} H- ,yAr2e2.y $Űx1uY捩v*t_CA\q\ƀMEgE рr~U2m֡Q1T@!,/?=!R0=$|g%*m6poF$IxWŶCn@4ciJyХ#jPҤ󾂨 CƂ0r%ifX!$ gjG`qQ!ݾC0:Y?8eNOG{}J^34W -jgs[nɱ;6 =-ְD% \̬1TS KPuF5*B,A3WdVi~eq5)IKDf 8 Qe7U>e0_PH Z*+.UF)vU6Q(Mv;jkѺ雃3b aE~ >W>~$s!jR\0f9Of-b:wCv3ּG"9tʿ6\K)8#mQO[6 & _(B 荴aV|DRj^KH@'" RbZ0Dɚ6rVGu3[n—y|uE#BkgИ ʌ}n05 ʇ0zՑagOMC *YyD(}{gKŰڥF2v>JDq/!]3~DaWVNV#3<=@ 2<>XrP po_+x Q ]!EǃRA-/33Uj?C6eh۽_ʥ!3h8֒0Ē#l*֞4] CRl&;q8'Zu9 i\:R;wxU(@iݸ6S?E&הoMBͮ5'" eq*DinO60 RJ5#ۋLU?%}ڕvXm f/ j>:i)2q"ExLIgd.1va_{X@9YiLII[ɹ"#Tv"YIQFDtfp(`pL}!gNPVE?EAA#g 'w[ظ}]cYm1 f;8$6c$z *)жB%dQxAn9^|:Dx<‘Y{✠6>p"[ݶ"hn䳹Ȃ acT 1.W% V#|$Tw7kpo%q؄4P((@C.uOy!$Қ4hPhInS]`ڎQԙy%Qf4')T!a{̮ 5y`sPM\ zeqQ_:X{ 6ݫcyIV)e%͇`D]r[ >?|*x員;V,jȳ׻γ䑠 i)J^:k3í(y>V3͛~ȷRΛ "E(#qa1g:ZbH?1 %&f Uh똪4<V+gn#mȓl;K3&o9R d$e "_9nxz/k ;GE -g H@manD88գ_7WIt:/^+ s `0$pyVMɈyøO,,}A!2Y)N70yR7cǂzkM'rȽ=9ftVz_dwH+ nS븷.2tf*I=(V[mOQCޯ`=MΣ0JDBfa&/,4.AA{\ %$l==L'5V =Ĕ%_Z`(HF@MX:Έy ѕ>lmgs `ddyg 24"8q^QvGmciYM^iTmK( O Xq%W3$BвEd+*qJ6bݨRxmgsom6tWJp$RvSd2 pג2^J(bV1`{VmGT榢 Q NX?Q{i@4j\wjx*Vb!v[ZqfA d*;iFV2j}Lb7 ф2A$E:`ڔ` 껀t6 qots> [R8Ƙ>x5o B3P weO0 yo YZ