sssd-tools-1.13.3-60.el6$>&^__$Y*bX>2?d   A *HNTbb b db b b b!xb#bb%L%hb&'9'9+9(,Z8,`93x:,GbHbIbXY\b]Db^4bdäeéfìlîCsssd-tools1.13.360.el6Userspace tools for use with the SSSDProvides userspace tools for manipulating users, groups, and nested groups in SSSD when using id_provider = local in /etc/sssd/sssd.conf. Also provides several other administrative tools: * sss_debuglevel to change the debug level on the fly * sss_seed which pre-creates a user entry for use in kickstarts * sss_obfuscate for generating an obfuscated LDAP password[)'Ox86-01.bsys.centos.org CentOSGPLv3+CentOS BuildSystem Applications/Systemhttp://fedorahosted.org/sssd/linuxi686+ɤKSA |5r#1FR :bo3^ 10m:+}MHOt ?tH dC A큤[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)'Vpn[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&6e0820314ea3ec7bc18b1a02ec3301dcb834a52ca671d60e8bbd6e8dda29149e10acab9502ce2e73014692130c887714ab86d0c8455e3ca3c60654dd1eb87dfbcbe626e51dc7fdf478397557ae7adf0452f253bc11ddad6cb89d4d5fa8fa20087f9c819356c2781dd47f9abe0138a5b58c00d63fba576d13b27ca1040181516e865c4f8b05fae82b77e7c3d36a6b73bd717a761d707845344c65ad8b31ac2846074ea22f08e186a8f16066958ff1cb7da80f4a744e9737ad3b619beac9b0a45e4b5ce8776a762c744f1a6baae5545d31d9d4bdcfd2db99a12ee83cd804192a1a38a9daf34044a114e85b3ee4965a4712cadb8857e38b24ca88328bcdd9c8941958dbe4f10a9270f7343dd9d7f90bb6ad02b51363ea969a23b8c4282e241ea075d09230a51dde5dac102de3ec991294200bd38d2e9a330a9bf9d551d987b0697948f560a1d2c5b425b6bc3cdfb439f6ba3335a7210d772475b29fff80ad4dc2848ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b90312faa0bc15ca0607109277f9e39c1d5b3f8f870b22ab03d9cd843dcb4937f23c898d9b4aefa781bcf8722e504fc5ac11f5d42eae2fb68dfe61122b8f98044a5d3d205d14a01e31bac7159e1ba9e65e1cd92e17b72af1eefd70fd8129c07bfa32a37e4f153c7948135315a93ebc523b5da3ff74134e37db1e58707f69f285995751ea01896d4b36ebfcaf460822c8e1fac3591ffb8062729702047d1feb185eb0306a72ed47048c15ba94b54fbe85fa0488662543060326e892178173483a35c79a25c04eac19642dd5c1de9c5715dca1978179971b917e21570b05010d9a51b6cbd6c2adb56fc77c0cb0e14d4575c99b507f6258409528ee860d6608f5a5f4e68fb90fe31e5abfbf19ea48c634aeb350f5c77d359556d5bddc40dd343e3210c50d992b8829d02b047b0aed7fbdeb05437563cb120618042e1607c36876699b64bb8e9a900564768929f88d57e798bdfdaa250ca225e051773c9cb698bbf9cbbdfce91ac10376053bb29a9e7be4ca3d0b44a5ee1c40066c9053b648581938913e6368ecccfc089afd5d2db3d4a993d685c9e24df43ba9b89905ef3da0ee317577d7359fe269dd50ceffa06e6d8b31d815fd3ffe14624f40d30bdedfbd186e803c731156edbde991952c524cb249c9291fc6f1f32a72b048bb8427ec889c6c3be2ae986e869623bbd719ab0b78d7f55a1c56ecf6349e6d4bd126636f890b355e35139fff8021748cc1c1f839ba681f08b2574bb6c7a5c95ed81a2eaa4f92cb927c5eefd7f14a2fe6dffc5e3daad37726aa63767189e2c6b14db2b80a8786fa81166f7519010c5f1a629c2b526106f60aa71352c22deac55026791058021208a55563394c60ede4701240cb3f1ad645d2f050d3fd896243dbbe21d0f918c1ca668ae1442c3ddb536dc94607fbff11a1653b979831a1ae879514a37a3b2967dc68bfa063fbf3e17dcf7a075908f24983b99d9a29ace2c27dc536673bce4f5c295ce806e2e3eca024c9d1c81c9ae926e676c74d2cf28f27cf696877a1ae201716e810a34443659f203bcc26033c99f1f44f636facad0a96186f185c4d00472e1feabdccccb36026a8c926867926b2f2c7a905415c3762260d12af95929b9446f51a1173bb88ad62e35bdb2a27feaccfcd7d8a24550b32aea3537e54e46866edf7a7b325b4546d68e849c368c0acf4416aa1683d9316a636f7a296424912a8943bda31b812282fd97808def916ad5340ab1201943355c75a31b4f60adf5bdee206dbb704998e25bb3b089fba27be6304650028b61ba8fa12f9bab1b7bbb5a94afa96ba8c6775d4712280211e0787dae108363ef3ba1d60b97e78a532362f0ca7f151995fcb93b3d7179c666a6f1ba4374e98880f3999b0d4c18be0b8c5690755ed6db5ffa1f41dc2848390ce1c1adc16d936d3bec7678d75df512aaa8c65ab05a2360edcc4f8eca8c6c7856f81172fafeb7b3fac9f6d2e4fcd7d2cbb3ee71259899900c70a0feeefe148e9380948617378f68caf855a74c6210ef6975dc2076f80092a54cd54279190b70df0e6ebafcd73e1d78c155d693289d3cade81c583a8b861197472ab6727f10207ec4bba8e70931c3c7fe84ba84ebcd657e3aa3058a8e4d1c9d3e47121dfed2cec72d72ecf81cebdc0e3c304edbfe18e7e03a8c92485d1b4dad2edbd20d665af641b9bb99993a41b4706733028b299fbcbe78c8befb5ef5395daf0302535a4b8b38a528c2f5e1447f05fea574c180504982cda4f30526999f9b097ae202cc188ff261fa7f8bc26dd13fc4e5699c549d4b181ded57e3c0720a9a6296ec70ce1fca467a8b2366d359e5f58532643db85c3896c5c2c2d3b2c68a41a713c4a4d055f6b739e2f6e77cf70dcb4307e82ae2b8ad9334c1fcfacf837e1de8cab1147201585bc8ecf5be5e1455af4c28bb081336f004cba4aec2e96ba5e93a0d6e9c554d9e7ceb6b78d89972e86b2f77e4a47c248930958cf35de382e8dbf61346453cd71b6673abbe15a9b68e0e1a9ca23df9475f8a49917be1474c238557624a79130062f62e9dfdb579f972293dec8ae2a4f083d349d624bb2ed68c952191737112f04ed07bc723c327a1cb950c81ebd12eaa17a35822e9cfa00211406f322dc890b40a04379300f907e65a8a541e706503102f4d8a5af3254f5a6f1c3c7cec4d9cbad94da713b12a9a70fa5fd5546dc97fca80c9f3115be2c4add4cbf8f405db62bec3d0a323d50892b5ba8ffe43407551dbd8be7a64fb1e89a335debddc88ddd59e8e10bb135e896310e43b55570617f0a750f8849740a7ce5831149544e5e45a8f85569ea29b3e521f27a3cb1418e8876d29be98db14b44c0e74c4384d2648368c6865b7de8bf97e183dbee9b1728ff2d7e085276f99c941493af78689d832a08118ac282947260339f85171549f5e1100155814458cb6ccb5e4494864990e6c2563b101fae7d70d85bb6dbdf2ca19d730d5587ce1a2b573ef44cc773338518ba1c10a4931d658c8703064c62c50d49c1dfe8e9053e1b7fa95856453a88e1e1cc56ce71772e1f8305d88fd591b2e437681a88c3f49d3ba9f0eea405562aa031a6fc9811410efde0bfb9150ab93167eb0c9742125a7b83f66615b57dc7c57da2d15b1bc49d4a2cab4a8f47af7ededd50cf8a6cf6c809a8fae4098a5d6d24a551458fafb42b3163c130edf0bc9424482ee50fad0ef35016888ee1ca7048d44f71c7f73ee5a535970fa8ad4fe6168897d9cdee7c7fc629f6c7ebf6f91d868aa237fc7eaded2b930313137764a5219ecbf43cb34c44edc46f9326f87fb8486c9fa7474184b14cfbe9a56fd3d94e453c3ba02c7da36cbc5304673d0b710fb0bf7685c2302ef9dda9600b606d122e91feb6e2186fe7b23dfad9d4119bc602b63b8fb841e07302111c6cf39ba94446af50f58e9389102129288b081d8e1273b13c622d958c18edc37fa36dda60f9af3cc4263c599c7b035a514407053884423412536b3126aa677c3994edf5f55e3fb0c4f1827d3ce5fe136083251bd6f207128f4919b7eb764584baacf0346e75f3467f9a1e0664b128b2ea2528ee22a48c7d1b360bc1493fead5f8a43f6a1d9c40bbf656c34abe221fd89740c6da946685148f966c8c378148f13ea8b2353d7c7737a509eeac64aa79423d69dd5e48e3d1ce70b89c012ad0c5ff21e2cc508d6cce293f343a1a9414d42a5e7ba039f982dc70c8c003f6a0aacf3215914efb1f85dc4ad65895b2a883be102f5bffd4b5447d9ece7b535c19112dd777d4d068848d84c51b13fd220519b87d8379fb8ad63d81f1f3a691e1879844a81229da8aa389b6e7236ddce33b6fea7acb7750642ebedf61beaff107e4d53e93592e5d84b85fad07f27bfe720b52deba680abc81b1729a6b6cda7f08b92cf7a7d61acb16d925390d1ce0a2ee2cb19d3f18245647d8e43c69c4b6309ac78ef674fbba769120dabce7cb535c2b0cf880ca163296d752dad7e464d6ad704c850b3804c8ec5b4355c88d8fee9c8b049b55558229481c0f7ec0ff83f557336738850452169ea02047a437e71c085aa5205550c9c5b54d77d51ee2f4e2ecd18c39550b260db95664b1b3eaad40ab0c33dd1545e3eb66c787d6fc4fc8a07428c12300db06f892645e41a5a2c1268c46db363ac492f3eaa69246ae4f4e15e6915f5e7648ce96721b7cf53f7a3f9357e26e15c0c58888370719041f9c5c098919ce2a37957d10a735a02e828cb555ee4b1371fb1e8f2459dfd94495534a2aa3529f515d066ff6b0051d70515e53b3cb52395128c684923c1a86de81bce6f77ade86fef840354705b578b2d4ce19e6df1becdaa80b818c5bd7236frootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-1.13.3-60.el6.src.rpmsssd-toolssssd-tools(x86-32)   @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ sssd-commonpython-ssspython-sssdconfigrpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(CompressedFileNames)libbasicobjects.so.0libcollection.so.4libc.so.6libc.so.6(GLIBC_2.0)libc.so.6(GLIBC_2.1)libc.so.6(GLIBC_2.2)libc.so.6(GLIBC_2.3)libc.so.6(GLIBC_2.3.4)libc.so.6(GLIBC_2.4)libc.so.6(GLIBC_2.6)libdbus-1.so.3libdhash.so.1libdhash.so.1(DHASH_0.4.3)libdl.so.2libglib-2.0.so.0libini_config.so.5liblber-2.4.so.2libldap-2.4.so.2libldb.so.1libldb.so.1(LDB_0.9.10)libnspr4.solibnss3.solibnssutil3.solibpcre.so.0libplc4.solibplds4.solibpopt.so.0libpopt.so.0(LIBPOPT_0)libpthread.so.0libpthread.so.0(GLIBC_2.0)libpthread.so.0(GLIBC_2.12)libpthread.so.0(GLIBC_2.2)libref_array.so.1librt.so.1libselinux.so.1libsemanage.so.1libsmime3.solibssl3.solibsss_cert.solibsss_child.solibsss_crypt.solibsss_debug.solibsss_semanage.solibsss_util.solibtalloc.so.2libtalloc.so.2(TALLOC_2.0.2)libtdb.so.1libtevent.so.0rtld(GNU_HASH)/usr/bin/pythonrpmlib(PayloadIsXz)1.13.3-60.el61.13.3-60.el61.13.3-60.el64.6.0-14.0-13.0.4-15.2-14.8.0ZH@ZH@Z2gYyX6@X6@XS@XOXJXGXF@X@X6@X6@X-X!@X!@X&X X X WWWW@W@W_@W_@WWW@W@W@W@Wi,@WYZ@WPWPV@VJVJVV@VՄ@VՄ@V@V&@V=@V=@V@V@V@VvV%@V%@V%@VVVVVpVii@V\:@VXEVV@VV@VV@VMV2 @Vf@Vf@Vf@UAUUuUn@UmUjUcUcUUUUUJ@UB@UB@U@U?v@U>$U8U.RU.RU-@U-@U-@U-@UF@UF@UUUUUU U U U@U@U@U@T9TTTTTTT@T@T~T~Tk4Tk4T$TTT@SvSvSvS%@S0S<@S<@S<@SSSSSSS/S/S;@SFS@S@S@S@S@S@Si@S@SSS!@SsZSpSNpS 4@S 4@RRRRRRfhRD!R1R%@R @R @RR|R|R|R|R|RRRRRRRRRRRRR@R@R@R@R@R@R@R@R@R@Q@Q@QQ*@Q?@QQvwQkQIQ5@Q0@Q']Q @PPPP@P@P@P-P@P@P@PDPDPDPDP[PPPPP@P@P@P@PPPPPPPP @P @P @P @P @P @Pf@PPPPP @P @P @P @P@P@P@PPPPPPPP@P@P@PpPpPpP@P@P@P@P@P@P@PP@PP@P@P@P@P@PPXPP{P{P{Pz@PqnPl(PaP`K@P#@Oĺ@O"O"OOO@OO~O@OOO@O@Ou@Ou@Oc+@O]@OYOOdON@OLOLOLOLOLO;@O5O1@ObN@NNNN@NNNj@NN$@N$@NN@N@Nx@Nm@Ng\N[@NTN?N:N:N:NNN|@M{@M{@Mߒ@M@M۝M۝M@MM@M@M3@MM>M>M@MM@M@Mx@MM=M=MwkMwkMv@MtMtMc@Mc@MbSM_MQ0@MJMGMA^@MA^@MA^@M.@M9L!L@L@L@L@LNLNL@L@LA@L@Lk@LYV@LRLI@L7@L(L_LLGKj@KK@KK@KK[K@KK~}@K]KY@KO@KKK/c@K+nK"4@KJJ@JJJkJJ@JJp9JlE@J?r@J0J,@IcIcIzI)@I)@I)@IV@IV@I@I@III@Fabiano Fidêncio - 1.13.3-60Fabiano Fidêncio - 1.13.3-59Fabiano Fidêncio - 1.13.3-58Jakub Hrozek - 1.13.3-57Lukas Slebodnik - 1.13.3-56Lukas Slebodnik - 1.13.3-55Jakub Hrozek - 1.13.3-54Jakub Hrozek - 1.13.3-53Jakub Hrozek - 1.13.3-52Jakub Hrozek - 1.13.3-51Jakub Hrozek - 1.13.3-50Jakub Hrozek - 1.13.3-49Jakub Hrozek - 1.13.3-48Jakub Hrozek - 1.13.3-47Jakub Hrozek - 1.13.3-46Jakub Hrozek - 1.13.3-45Jakub Hrozek - 1.13.3-44Jakub Hrozek - 1.13.3-43Jakub Hrozek - 1.13.3-42Jakub Hrozek - 1.13.3-41Jakub Hrozek - 1.13.3-40Jakub Hrozek - 1.13.3-39Jakub Hrozek - 1.13.3-38Jakub Hrozek - 1.13.3-37Jakub Hrozek - 1.13.3-36Jakub Hrozek - 1.13.3-35Jakub Hrozek - 1.13.3-34Jakub Hrozek - 1.13.3-33Jakub Hrozek - 1.13.3-32Jakub Hrozek - 1.13.3-31Jakub Hrozek - 1.13.3-30Jakub Hrozek - 1.13.3-29Jakub Hrozek - 1.13.3-28Jakub Hrozek - 1.13.3-27Jakub Hrozek - 1.13.3-26Jakub Hrozek - 1.13.3-25Jakub Hrozek - 1.13.3-24Jakub Hrozek - 1.13.3-23Jakub Hrozek - 1.13.3-22Jakub Hrozek - 1.13.3-21Jakub Hrozek - 1.13.3-20Jakub Hrozek - 1.13.3-19Jakub Hrozek - 1.13.3-18Jakub Hrozek - 1.13.3-17Jakub Hrozek - 1.13.3-16Jakub Hrozek - 1.13.3-15Jakub Hrozek - 1.13.3-14Jakub Hrozek - 1.13.3-14Jakub Hrozek - 1.13.3-13Jakub Hrozek - 1.13.3-12Jakub Hrozek - 1.13.3-11Jakub Hrozek - 1.13.3-10Jakub Hrozek - 1.13.3-9Jakub Hrozek - 1.13.3-8Jakub Hrozek - 1.13.3-7Jakub Hrozek - 1.13.3-6Jakub Hrozek - 1.13.3-5Jakub Hrozek - 1.13.3-4Jakub Hrozek - 1.13.3-3Jakub Hrozek - 1.13.3-2Jakub Hrozek - 1.13.3-1Jakub Hrozek - 1.13.2-7Jakub Hrozek - 1.13.2-6Jakub Hrozek - 1.13.2-5Jakub Hrozek - 1.13.2-4Jakub Hrozek - 1.13.2-3Jakub Hrozek - 1.13.2-2Jakub Hrozek - 1.13.2-1Jakub Hrozek - 1.13.1-1Jakub Hrozek - 1.12.4-51Jakub Hrozek - 1.12.4-50Jakub Hrozek - 1.12.4-49Jakub Hrozek - 1.12.4-48Jakub Hrozek - 1.12.4-47Jakub Hrozek - 1.12.4-46Jakub Hrozek - 1.12.4-45Jakub Hrozek - 1.12.4-44Jakub Hrozek - 1.12.4-43Jakub Hrozek - 1.12.4-42Jakub Hrozek - 1.12.4-41Jakub Hrozek - 1.12.4-40Jakub Hrozek - 1.12.4-39Jakub Hrozek - 1.12.4-38Jakub Hrozek - 1.12.4-37Jakub Hrozek - 1.12.4-36Jakub Hrozek - 1.12.4-35Jakub Hrozek - 1.12.4-34Jakub Hrozek - 1.12.4-33Jakub Hrozek - 1.12.4-32Jakub Hrozek - 1.12.4-31Jakub Hrozek - 1.12.4-30Jakub Hrozek - 1.12.4-29Jakub Hrozek - 1.12.4-28Jakub Hrozek - 1.12.4-27Jakub Hrozek - 1.12.4-26Jakub Hrozek - 1.12.4-25Jakub Hrozek - 1.12.4-24Jakub Hrozek - 1.12.4-23Jakub Hrozek - 1.12.4-22Jakub Hrozek - 1.12.4-21Jakub Hrozek - 1.12.4-20Jakub Hrozek - 1.12.4-19Jakub Hrozek - 1.12.4-18Jakub Hrozek - 1.12.4-17Jakub Hrozek - 1.12.4-16Jakub Hrozek - 1.12.4-15Jakub Hrozek - 1.12.4-14Jakub Hrozek - 1.12.4-13Jakub Hrozek - 1.12.4-12Jakub Hrozek - 1.12.4-11Jakub Hrozek - 1.12.4-10Jakub Hrozek - 1.12.4-9Jakub Hrozek - 1.12.4-8Jakub Hrozek - 1.12.4-7Jakub Hrozek - 1.12.4-6Jakub Hrozek - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Jakub Hrozek - 1.12.4-2Jakub Hrozek - 1.12.4-1Jakub Hrozek - 1.11.6-33Jakub Hrozek - 1.11.6-32Jakub Hrozek - 1.11.6-31Jakub Hrozek - 1.11.6-30Jakub Hrozek - 1.11.6-29Jakub Hrozek - 1.11.6-28Jakub Hrozek - 1.11.6-27Jakub Hrozek - 1.11.6-26Jakub Hrozek - 1.11.6-25Jakub Hrozek - 1.11.6-24Jakub Hrozek - 1.11.6-23Jakub Hrozek - 1.11.6-22Jakub Hrozek - 1.11.6-21Jakub Hrozek - 1.11.6-20Jakub Hrozek - 1.11.6-19Jakub Hrozek - 1.11.6-18Jakub Hrozek - 1.11.6-17Jakub Hrozek - 1.11.6-16Jakub Hrozek - 1.11.6-15Jakub Hrozek - 1.11.6-14Jakub Hrozek - 1.11.6-13Jakub Hrozek - 1.11.6-12Jakub Hrozek - 1.11.6-11Jakub Hrozek - 1.11.6-10Jakub Hrozek - 1.11.6-9Jakub Hrozek - 1.11.6-8Jakub Hrozek - 1.11.6-7Jakub Hrozek - 1.11.6-6Jakub Hrozek - 1.11.6-5Jakub Hrozek - 1.11.6-4Jakub Hrozek - 1.11.6-3Jakub Hrozek - 1.11.6-2Jakub Hrozek - 1.11.6-1Jakub Hrozek - 1.11.5.1-4Jakub Hrozek - 1.11.5.1-3Jakub Hrozek - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Jakub Hrozek - 1.9.2-134Jakub Hrozek - 1.9.2-133Jakub Hrozek - 1.9.2-132Jakub Hrozek - 1.9.2-131Jakub Hrozek - 1.9.2-130Jakub Hrozek - 1.9.2-129Jakub Hrozek - 1.9.2-128Jakub Hrozek - 1.9.2-127Jakub Hrozek - 1.9.2-126Jakub Hrozek - 1.9.2-125Jakub Hrozek - 1.9.2-124Jakub Hrozek - 1.9.2-123Jakub Hrozek - 1.9.2-122Jakub Hrozek - 1.9.2-121Jakub Hrozek - 1.9.2-120Jakub Hrozek - 1.9.2-119Jakub Hrozek - 1.9.2-118Jakub Hrozek - 1.9.2-117Jakub Hrozek - 1.9.2-116Jakub Hrozek - 1.9.2-115Jakub Hrozek - 1.9.2-114Jakub Hrozek - 1.9.2-113Jakub Hrozek - 1.9.2-112Jakub Hrozek - 1.9.2-111Jakub Hrozek - 1.9.2-110Jakub Hrozek - 1.9.2-109Jakub Hrozek - 1.9.2-108Jakub Hrozek - 1.9.2-107Jakub Hrozek - 1.9.2-106Jakub Hrozek - 1.9.2-105Jakub Hrozek - 1.9.2-104Jakub Hrozek - 1.9.2-103Jakub Hrozek - 1.9.2-102Jakub Hrozek - 1.9.2-101Jakub Hrozek - 1.9.2-100Jakub Hrozek - 1.9.2-99Jakub Hrozek - 1.9.2-98Jakub Hrozek - 1.9.2-97Jakub Hrozek - 1.9.2-96Jakub Hrozek - 1.9.2-95Jakub Hrozek - 1.9.2-94Jakub Hrozek - 1.9.2-93Jakub Hrozek - 1.9.2-92Jakub Hrozek - 1.9.2-91Jakub Hrozek - 1.9.2-90Jakub Hrozek - 1.9.2-89Jakub Hrozek - 1.9.2-88Jakub Hrozek - 1.9.2-87Jakub Hrozek - 1.9.2-86Jakub Hrozek - 1.9.2-85Jakub Hrozek - 1.9.2-84Jakub Hrozek - 1.9.2-83Jakub Hrozek - 1.9.2-82Jakub Hrozek - 1.9.2-81Jakub Hrozek - 1.9.2-80Jakub Hrozek - 1.9.2-79Jakub Hrozek - 1.9.2-78Jakub Hrozek - 1.9.2-77Jakub Hrozek - 1.9.2-76Jakub Hrozek - 1.9.2-75Jakub Hrozek - 1.9.2-74Jakub Hrozek - 1.9.2-73Jakub Hrozek - 1.9.2-72Jakub Hrozek - 1.9.2-71Jakub Hrozek - 1.9.2-70Jakub Hrozek - 1.9.2-69Jakub Hrozek - 1.9.2-68Jakub Hrozek - 1.9.2-67Jakub Hrozek - 1.9.2-66Jakub Hrozek - 1.9.2-65Jakub Hrozek - 1.9.2-64Jakub Hrozek - 1.9.2-63Jakub Hrozek - 1.9.2-62Jakub Hrozek - 1.9.2-61Jakub Hrozek - 1.9.2-60Jakub Hrozek - 1.9.2-59Jakub Hrozek - 1.9.2-58Jakub Hrozek - 1.9.2-57Jakub Hrozek - 1.9.2-56Jakub Hrozek - 1.9.2-55Jakub Hrozek - 1.9.2-54Jakub Hrozek - 1.9.2-53Jakub Hrozek - 1.9.2-52Jakub Hrozek - 1.9.2-51Jakub Hrozek - 1.9.2-50Jakub Hrozek - 1.9.2-49Jakub Hrozek - 1.9.2-48Jakub Hrozek - 1.9.2-47Jakub Hrozek - 1.9.2-46Jakub Hrozek - 1.9.2-45Jakub Hrozek - 1.9.2-44Jakub Hrozek - 1.9.2-43Jakub Hrozek - 1.9.2-42Jakub Hrozek - 1.9.2-41Jakub Hrozek - 1.9.2-40Jakub Hrozek - 1.9.2-39Jakub Hrozek - 1.9.2-38Jakub Hrozek - 1.9.2-37Jakub Hrozek - 1.9.2-36Jakub Hrozek - 1.9.2-35Jakub Hrozek - 1.9.2-34Jakub Hrozek - 1.9.2-33Jakub Hrozek - 1.9.2-32Jakub Hrozek - 1.9.2-31Jakub Hrozek - 1.9.2-30Jakub Hrozek - 1.9.2-29Jakub Hrozek - 1.9.2-28Jakub Hrozek - 1.9.2-27Jakub Hrozek - 1.9.2-26Jakub Hrozek - 1.9.2-25Jakub Hrozek - 1.9.2-24Jakub Hrozek - 1.9.2-23Jakub Hrozek - 1.9.2-22Jakub Hrozek - 1.9.2-21Jakub Hrozek - 1.9.2-20Jakub Hrozek - 1.9.2-20Jakub Hrozek - 1.9.2-19Jakub Hrozek - 1.9.2-18Jakub Hrozek - 1.9.2-17Jakub Hrozek - 1.9.2-16Jakub Hrozek - 1.9.2-15Jakub Hrozek - 1.9.2-14Jakub Hrozek - 1.9.2-13Jakub Hrozek - 1.9.2-12Jakub Hrozek - 1.9.2-11Jakub Hrozek - 1.9.2-10Jakub Hrozek - 1.9.2-9Jakub Hrozek - 1.9.2-8Jakub Hrozek - 1.9.2-7Jakub Hrozek - 1.9.2-6Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-3Jakub Hrozek - 1.9.0-2Jakub Hrozek - 1.9.0-1.rc1Jakub Hrozek - 1.8.0-33Stephen Gallagher - 1.8.0-32Stephen Gallagher - 1.8.0-31Stephen Gallagher - 1.8.0-30Stephen Gallagher - 1.8.0-29Stephen Gallagher - 1.8.0-28Stephen Gallagher - 1.8.0-27Stephen Gallagher - 1.8.0-26Stephen Gallagher - 1.8.0-25Stephen Gallagher - 1.8.0-24Stephen Gallagher - 1.8.0-23Stephen Gallagher - 1.8.0-22Stephen Gallagher - 1.8.0-21Stephen Gallagher - 1.8.0-20Stephen Gallagher - 1.8.0-18Stephen Gallagher - 1.8.0-17Stephen Gallagher - 1.8.0-15Stephen Gallagher - 1.8.0-12Stephen Gallagher - 1.8.0-11Stephen Gallagher - 1.8.0-10Stephen Gallagher - 1.8.0-9Stephen Gallagher - 1.8.0-8Stephen Gallagher - 1.8.0-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5Stephen Gallagher - 1.8.0-4.beta3Stephen Gallagher - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-2.beta2Stephen Gallagher - 1.5.1-68Stephen Gallagher - 1.5.1-67Stephen Gallagher - 1.5.1-66Stephen Gallagher - 1.5.1-65Stephen Gallagher - 1.5.1-64Stephen Gallagher - 1.5.1-63Stephen Gallagher - 1.5.1-62Stephen Gallagher - 1.5.1-61Stephen Gallagher - 1.5.1-60Stephen Gallagher - 1.5.1-59Stephen Gallagher - 1.5.1-58Stephen Gallagher - 1.5.1-57Stephen Gallagher - 1.5.1-56Stephen Gallagher - 1.5.1-55Stephen Gallagher - 1.5.1-53Stephen Gallagher - 1.5.1-52Stephen Gallagher - 1.5.1-51Stephen Gallagher - 1.5.1-50Stephen Gallagher - 1.5.1-49Stephen Gallagher - 1.5.1-48Stephen Gallagher - 1.5.1-47Stephen Gallagher - 1.5.1-46Stephen Gallagher - 1.5.1-45Stephen Gallagher - 1.5.1-44Stephen Gallagher - 1.5.1-43Stephen Gallagher - 1.5.1-42Stephen Gallagher - 1.5.1-41Stephen Gallagher - 1.5.1-40Stephen Gallagher - 1.5.1-39Stephen Gallagher - 1.5.1-38Stephen Gallagher - 1.5.1-37Stephen Gallagher - 1.5.1-36Stephen Gallagher - 1.5.1-35Stephen Gallagher - 1.5.1-34Stephen Gallagher - 1.5.1-33Stephen Gallagher - 1.5.1-32Stephen Gallagher - 1.5.1-31Stephen Gallagher - 1.5.1-30Stephen Gallagher - 1.5.1-29Stephen Gallagher - 1.5.1-28Stephen Gallagher - 1.5.1-27Stephen Gallagher - 1.5.1-26Stephen Gallagher - 1.5.1-25Stephen Gallagher - 1.5.1-24Stephen Gallagher - 1.5.1-23Stephen Gallagher - 1.5.1-21Stephen Gallagher - 1.5.1-20Stephen Gallagher - 1.5.1-17Stephen Gallagher - 1.5.1-16Stephen Gallagher - 1.5.1-15Stephen Gallagher - 1.5.1-14Stephen Gallagher - 1.5.1-13Stephen Gallagher - 1.5.1-12Stephen Gallagher - 1.5.1-11Stephen Gallagher - 1.5.1-10Stephen Gallagher - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Stephen Gallagher - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.2.1-28.4Stephen Gallagher - 1.2.1-36Stephen Gallagher - 1.2.1-35Stephen Gallagher - 1.2.1-28.3Stephen Gallagher - 1.2.1-34Stephen Gallagher - 1.2.1-28.2Stephen Gallagher - 1.2.1-33Stephen Gallagher - 1.2.1-28.1Stephen Gallagher - 1.2.1-32Stephen Gallagher - 1.2.1-29Stephen Gallagher - 1.2.1-28Stephen Gallagher - 1.2.1-27Stephen Gallagher - 1.2.1-26Stephen Gallagher - 1.2.1-23Stephen Gallagher - 1.2.1-21Stephen Gallagher - 1.2.1-20Stephen Gallagher - 1.2.1-19Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-14Stephen Gallagher - 1.2.0-13Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11.1Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Related: rhbz#1442703 - Smart Cards: Certificate in the ID View - Related: rhbz# 1401546 - Please back-port fast failover from sssd 1.14 on RHEL 7 into sssd 1.13 on RHEL 6- Resolves: rhbz#1326007 - Memory cache corruption when rsync and/or tar to copy owner and group info from LDAP - Resolves: rhbz#1442703 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1507435 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-6.10] - Resolves: rhbz#1487040 - sssd does not evaluate AD UPN suffixes which results in failed user logins- Resolves: rhbz#1421057 - pam_sss crashes in do_pam_conversation if no conversation function is provided by the client app - Resolves: rhbz#1487040 - sssd does not evaluate AD UPN suffixes which results ini failed user logins - Resolves: rhbz#1487944 - ABRT crash - /usr/libexec/sssd/sssd_nss - Resolves: rhbz#1489485 - sssd is not pulling groups in a trusted domain, with the Global scope- Resolves: rhbz#1438360 - The originalMemberOf attribute disappears from the cache, causing intermittent HBAC issues- Resolves: rhbz#1404697 - SSSD does not skip GPO if no gpcFunctionalityVersion present - Resolves: rhbz#1374813 - SSSD fails to process GPO from Active Directory- Resolves: rhbz#1415785 - ldap_child does not remove temporary files when it's killed with SIGTERM- Apply several more smartcard-related patches. - Related: rhbz#1300421 - Screen locks and smart card is removed - must show a message to insert the correct smartcard- Resolves: rhbz#1400643 - sssd prevents sudo from getting data from LDAP- Resolves: rhbz#1393592 - SSH-CERT: always initialize cert_verify_opts- Revert the ding-libs requirement - Related: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Related: rhbz#1369921 - Members of nested netgroups configured in IdM cannot be seen by getent on clients- Require the matching version of ding-libs - Related: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Fix a coverity warning - Related: rhbz#1382395 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1382395 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1369921 - Members of nested netgroups configured in IdM cannot be seen by getent on clients- Resolves: rhbz#1324428 - [RFE] Discover forest's root SID even if subdomains_provider = none- Resolves: rhbz#1367802 - using overides causes segfault in libldb- Resolves: rhbz#1329378 - pam_sss set KRB5CCNAME with sudo logins- Resolves: rhbz#1382603 - autofs map resolution doesn't work offline- Resolves: rhbz#1339986 - [sssd-ldap] man page needs attention- Resolves: rhbz#1321884 - IPA sudo: support the externalUser attribute- Resolves: rhbz#1299994 - ssh client checks only the first certificate on a smartcard when the card has multiple certs - Resolves: rhbz#1300421 - Screen locks and smart card is removed - must show a message to insert the correct smartcard - Resolves: rhbz#1372681 - ssh with Smartcards - skip invalid certificates- Resolves: rhbz#1329648 - Protocol error with IPA on RHEL-6 - Resolves: rhbz#1329647 - IPA view: view name not stored properly with default FreeIPA installation- Resolves: rhbz#1339986 - [sssd-ldap] man page needs attention- Resolves: rhbz#1327272 - local overrides: issues with sub-domain users and mixed case names- Resolves: rhbz#1293168 - Inconsistent user synching between IPA and AD- Resolves: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Resolves: rhbz#1377782 - sssd is looking at a server in the GC of a subdomain, not the root domain.- Resolves: rhbz#1365218 - SSSD does not fail over to next GC- Resolves: rhbz#1367435 - Intermittent sssd auth failures- Resolves: rhbz#1369079 - sssd runs out of available child slots and starts queuing requests in proxy mode- Resolves: rhbz#1338619 - segmentation fault in sssd after upgrade to sssd-1.13.3-22.el6.x86_64 when upgrading cache- Resolves: rhbz#1324107 - GPO: Access denied after blocking connection to AD.- Resolves: rhbz#1293168 - Inconsistent user synching between IPA and AD- Resolves: rhbz#1340927 - sssd-common requires libnfsidmap- Resolves: rhbz#1340176 - The AD keytab renewal task leaks a file descriptor- Resolves: rhbz#1335400 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1336453 - sssd_be doesn't terminate forked child process if adcli is not installed- Resolves: rhbz#1312062 - sssd does not pass LDAP rules to sudo- Resolves: rhbz#1313940 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo- Actually apply patches from previous build - Resolves: rhbz#1313940 - sudorule not working with ipa sudo_provider- Resolves: rhbz#1313940 - sudorule not working with ipa sudo_provider- Resolves: rhbz#1209600 - Getting ERROR (getpwnam() failed): Broken pipe with 1.11.6- Backport of a more minimal dependency patch to avoid changes to AD provider behaviour - Related: rhbz#1264705 - Allow SSSD to notify user of denial due to AD account lockout- Resolves: rhbz#1308939 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user- Require a newer selinux-policy to avoid issues when prompting for SC PIN - Related: rhbz#1299066 - smartcard login does not prompt for pin when ocsp checking is enabled (default config)- Resolves: rhbz#1264705 - Allow SSSD to notify user of denial due to AD account lockout- Resolves: rhbz#1259687 - sssd_nss memory usage keeps growing on sssd-1.12.4-47.el6.x86_64 (RHEL6.7) when trying to retrieve non-existing netgroups- Update sssd-ldap man page for the recent ID mapping changes - Related: rhbz#1268902 - SSSD doesn't set the ID mapping range automatically- Resolves: rhbz#1295883 - refresh_expired_interval stops sss_cache from working- Resolves: rhbz#1268902 - SSSD doesn't set the ID mapping range automatically- Resolves: rhbz#1298253 - Screen lock prompts for smartcard user password and not smartcard pin when logged in using smartcard pin- Resolves: rhbz#1292458 - sssd_be AD segfaults on missing A record- Resolves: rhbz#1262981 - sssd dereference processing failed : Input/output error- Resolves: rhbz#1290761 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs- Resolves: rhbz#1244957 - [RFE] SUDO: Support the IPA schema- Resolves: rhbz#1298634 - Cannot retrieve users after upgrade from 1.12 to 1.13- Resolves: rhbz#1287807 - SRV lookup for KDC servers doesn't work- Resolves: rhbz#1273802 - ad_site parameter does not work- Fix memory leak in the NFS plugin - Related: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - Resolves: rhbz#1296620 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1283898 - MAN: Clarify that subdomains always use service discovery- Rebase to 1.13.3 - Remove setuid bit from proxy_child, RHEL-6 doesn't support running SSSD as a non-privileged user - Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8- Don't own files as the SSSD user - Resolves: rhbz#1289482 - warning: user sssd does not exist - using root- Resolves: rhbz#1279971 - groups get deleted from the cache- The p11_child doesn't have to run privileged anymore, remove the setuid bit - Related: rhbz#1270027 - [RFE] Support for smart cards- Resolves: rhbz#1266108 - Check next certificate on smart card if first is not valid - Also enable OCSP checks- Resolves: rhbz#1285852 - sssd: [sysdb_add_user] (0x0400): Error: 17 (File exists)- Silence compilation warnings and Coverity issues - Related: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8- Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - Squash in packaging review changes by lslebodn@redhat.com- Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - The rebase also resolves the following bugzillas: - Resolves: rhbz#1270029 - [RFE] Add a way to lookup users based on CAC identity certificates - Resolves: rhbz#1270027 - [RFE] Support for smart cards - Resolves: rhbz#1269422 - [FEAT] UID and GID mapping on individual clients - Resolves: rhbz#1269421 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#1265429 - If the site discovery fails, ad-site option is not taken into account. - Resolves: rhbz#1254193 - Fix for cyclic dependencies between sssd-{krb5,}-common - Resolves: rhbz#1247997 - [IPA/IdM] sudoOrder not honored as expected - Resolves: rhbz#1237142 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1232632 - Kerberos-based providers other than krb5 do not queue requests - Resolves: rhbz#1227804 - Group members are not turned into ghost entries when the user is purged from the SSSD cache - Resolves: rhbz#1227685 - sssd with ldap backend throws error domain log - Resolves: rhbz#1221365 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1215195 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1196204 - sssd cache holding gid values for nss, but not the alpha group name representation - Resolves: rhbz#1194039 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD- Resolves: rhbz#1266404 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1264524 - SSSD POSIX attribute check is too strict- Resolves: rhbz#1255285 - cleanup_groups should sanitize dn of groups- Resolves: rhbz#1251349 - sysdb sudo search doesn't escape special characters- Resolves: rhbz#1232738 - Cache is not updated after user is deleted from ldap server- Resolves: rhbz#1227860 - Provide a way to disable the cleanup task - Resolves: rhbz#1227863 - ignore_group_members doesn't work for subdomains- Resolves: rhbz#1226834 - id lookup for non-root domain users doesn't return all groups on first attempt- Resolves: rhbz#1225614 - IPA enumeration provider crashes- Resolves: rhbz#1212610 - sssd ad groups work intermittently- Resolves: rhbz#1215765 - sssd nss responder gets wrong number of secondary groups- Resolves: rhbz#1221358 - SSSD doesn't work with ID mapping and disabled subdomains- Resolves: rhbz#1219844 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust- Resolves: rhbz#1216094 - /usr/libexec/sssd/selinux_child crashes and gets avc denial when ssh- Include several upstream fixes related to ID views - Resolves: rhbz#1215195 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1213947 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1213822 - Overrides with --login work in second attempt- Resolves: rhbz#1217328 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set- Resolves: rhbz#1212387 - sssd_be segfault id_provider = ad src/providers/ad/ad_gpo.c:843- Resolves: rhbz#1213940 - Overridde with --login fails trusted adusers group membership resolution- Resolves: rhbz#1170910 - SSSD should not fail authentication when only allow rules are used- Resolves: rhbz#1213716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1213822 - Overrides with --login work in second attempt- Resolves: rhbz#1212017 - Sudo responder does not respect filter_users and filter_groups- Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only- Related: rhbz#1211728 - Only set the selinux context if the context differs from the local one- Package the localauth plugin - Related: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Resolves: rhbz#1207720 - id lookup resolves "Domain Local" group and errors appear in domain log- BuildRequire the proper libkrb5 version for correct localauth plugin build - Related: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Resolves: rhbz#1194367 - sssd_be dumping core- Resolves: rhbz#1206121 - ldap_access_order=ppolicy: Explicitly mention in manpage that unsupported time specification will lead to sssd denying access- Resolves: rhbz#1205382 - Properly handle AD's binary objectGUID- Resolves: rhbz#1205716 - Installing sssd-common-1.12.4-18.el6 might install with wrong user account (root)- Fix a typo in DEBUG message - Related: rhbz#1173198 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires- Handle TTL=0 in SRV queries correctly - Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query- Cherry-pick unit test changes from upstream to allow cherry-picking sssd-1-12 patches - Remove unused LDAP provider code to avoid static analyser warnings - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1206092 - sssd crashes intermittently in GPO code- Resolves: rhbz#1202728 - sssd-ad requires samba3, but ipa-server-trust-ad requires samba4- Resolves: rhbz#1203630 - SSSD doesn't own the GPO cache directory- Fix warning in SELinux code - Handle setups with empty default and no SELinux maps - Related: rhbz#1194302 - With empty ipaselinuxusermapdefault security context on client is staff_u - Resolves: rhbz#1202305 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605 - Resolves: rhbz#1201847 - SSSD downloads too much information when fetching information about groups- Fix PAM responder initgroups cache for subdomain users - Log extop failures better - Related: rhbz#1168344 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Fix internal error codes broken when fixing rhbz#1036745 - Related: rhbz#1036745 - [RFE] Allow SSSD to issue shadow expiration warning even if alternate authentication method is used- Resolves: rhbz#1200093 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything- Fix Coverity warning in ldap_child - Add better debugging - Related: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1098147 - [RFE] Implement background refresh for users, groups or other cache objects- Resolves: rhbz#1173198 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires- Initialize a pointer in ldap_child to NULL - Resolves: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Relax the ldb requirement - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1194302 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query- Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query - Rebuild against latest krb5, add a versioned BuildRequires - Resolves: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Related: rhbz#1036745 - [RFE] Allow SSSD to issue shadow expiration warning even if alternate authentication method is used- Do not mark the selinux_child helper as setuid, we don't support rootless SSSD in 6.7 - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1168347 - Rebase sssd to 1.12.x - The rebase resolves the following RHEL bugzillas - Resolves: rhbz#1172865 - sssd.conf(5) man page gives bad advice about domains parameter - Resolves: rhbz#1172494 - PAC: krb5_pac_verify failures should not be fatal (backport fix from upstream) - Resolves: rhbz#1171782 - [RFE]: SSSD should preserve case for user uid field - Resolves: rhbz#1170910 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1168377 - [RFE] User's home directories and shells are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1168363 - [RFE] Add domains= option to pam_sss - Resolves: rhbz#1168344 - [RFE] ID Views: Support migration from the sync solution to the trust solution - Resolves: rhbz#1161564 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1148582 - inconsistent group information when multiple ad domain sections are configured in sssd - Resolves: rhbz#1140909 - sssd.conf man page missing subdomains_provider ad support - Resolves: rhbz#1139878 - SSSD connection terminated after failing anonymous bind to IBM Tivoli Directory Server - Resolves: rhbz#1135838 - Man sssd-ldap shows parameter ldap_purge_cache_timeout with "Default: 10800 (12 hours)" - Resolves: rhbz#1135432 - Dereference code errors out when dereferencing entries protected by ACIs - Resolves: rhbz#1134942 - sssd does not recognize Windows server 2012 R2's LDAP as AD - Resolves: rhbz#1123291 - automount segfaults in sss_nss_check_header - Resolves: rhbz#1088402 - [RFE] Allow login through SSSD using multiple attributes- Resolves: rhbz#1154042 - RHEL6.6 sssd (1.11) doesn't return all group memberships against an IPA server- Resolves: rhbz#1160713 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1141814 - Password expiration policies are not being enforced by SSSD- Resolves: rhbz#1139044 - RHEL6.6 ipa user private group not found- Resolves: rhbz#1103487 - CVE-2014-0249 - sssd: incorrect expansion of group membership when encountering a non-POSIX group- Resolves: rhbz#1125187 - simple_allow_groups does not lookup groups from other AD domains- Resolves: rhbz#1127270 - sssd connect to ipa-server is long- Resolves: rhbz#1130017 - Saving group membership fails if provider is AD, POSIX attributes are used and primary group contains the user as a member- Resolves: rhbz#1111528 - Expired shadow policy user(shadowLastChange=0) is not prompted for password change- Resolves: rhbz#1132361 - use-after-free in dyndns code- Resolves: rhbz#1099290: RFE: Be able to configure sssd to honor openldap account lock to restrict access via ssh key- Use the correct sudo iterator - Related: rhbz#1118336 - sudo: invalid sudoHost filter with asterisk- Add notes about offline mode to sssd.conf - Related: rhbz#1110226 - Requests queued during transition from offline to online mode- Resolves: rhbz#1127278 - Auth fails when space in username is replaced with character set by override_default_whitespace- Resolves: rhbz#1127757 - sssd can't retrieve sudo rules when using the "default_domain_suffix" option- Resolves: rhbz#1127265 - Problems with tokengroups and ldap_group_search_base- Resolves: rhbz#1126636 - RHEL6.6 sssd not running after upgrade- Resolves: rhbz#1128612 - IFP: FQDN lookups are broken- Resolves: rhbz#1118336 - sudo: invalid sudoHost filter with asterisk- Resolves: rhbz#1110226 - Requests queued during transition from offline to online mode- Resolves: rhbz#1122873 - Failover does not always happen from SRV to hostname resolution(via /etc/hosts) - Remove spurious systemctl call on %postun- Resolves: rhbz#1111317 - [RFE] Add option for sssd to replace space with specified character in LDAP group- Resolves: rhbz#1109188 - dereferencing control failure against openldap server- Resolves: rhbz#1084532 - sssd_sudo process segfaults- Resolves: rhbz#1122158 - ad: group membership is empty when id mapping is off and tokengroups are enabled- Resolves: rhbz#1118541 - Floating point exception using ldap- Resolves: rhbz#1042922 - [RFE] Add fallback to sudoRunAs when sudoRunAsUser is not defined and no ldap_sudorule_runasuser mapping has been defined in SSSD- Resolves: rhbz#1120508 - tokengroups do not work with id_provider=ldap- Fix potential NULL dereference in IFP code - Related: rhbz#1110369 - sssd is started before messagebus, making sssd-ifp fail- BuildRequire the latest libini_config - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Resolves: rhbz#1110369 - sssd is started before messagebus, making sssd-ifp fail- Resolves: rhbz#1104145 - public key validator is too strict and does not allow newlines anywhere in the public key string, not even at the end- Rebase to 1.11.6 - Resolves: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Rebuild against new ding-libs - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Backport the InfoPipe patches needed for Sat6 integration - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Resolves: #1085412 - SSSD Crashes when storage experiences high latency- Resolves: #1051164 - Rebase SSSD to 1.11+ in RHEL6Resolves: #1036168 - sssd can't retrieve auto.master when using the "default_domain_suffix"- Resolves: #1065534 - SSSD pam module accepts usernames with leading spaces- Resolves: #1038098 - sssd_nss grows memory footprint when netgroups are requested- Allow combination of proxy id backend and LDAP auth backend - Resolves: #1025813 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Inherit UID limits for subdomains - Resolves: #1020905 - Creating system accounts on a IdM client takes up to 10 minutes when AD trust is configured in the IdM.- Do not crash when LDAP disconnects while a search is still in progress - Resolves: #1019979 - sssd_be segfault when authenticating against active directory- More upstream fixes to prevent memcache crashes - Related: #997406 - sssd_nss core dumps under load- Resolves: #1002929 - sssd_be segfaults if IPA dynamic DNS update times out- Make IPA SELinux provider aware of subdomain users - A better version of already committed patch - Resolves: #954342 - In IPA AD trust setup, the sssd logs throws 'sysdb_search_user_by_name failed' error when AD user tries to login via ipa client.- Resolves: #997406 - sssd_nss core dumps under load - Resolves: #984814 - sssd_nss terminated with segmentation fault- Resolves: #1002161 - large number of sudo rules results in error - Unable to create response: Invalid argument- Silence restorecon on clean install - Resolves: #987456 - RHEL6 sssd upgrade restorecon workaround for /var/lib/sss/mc context- Make IPA SELinux provider aware of subdomain users - Resolves: #954342 - In IPA AD trust setup, the sssd logs throws 'sysdb_search_user_by_name failed' error when AD user tries to login via ipa client.- Print password complexity hint when password change fails with constraint violation - Related: #983028 - passwd returns "Authentication token manipulation error" when entering wrong current password- Resolves: #983028 - passwd returns "Authentication token manipulation error" when entering wrong current password- Resolves: #948830 - sssd do too many disk writes causing delay in "getent netgroup allmachines-netgroup" nested netgroups.- Resolves: #984814 - sssd_nss terminated with segmentation fault- Resolves: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- Resolves: #963235 - sssd_be crashing with nested ldap groups- Apply a forgotten dependency for patch #254 - Related: #916997 - getgrnam / getgrgid for large user groups is too slow due to range retrieval functionality - Add two fixes for better handling of faulty SRV processing - Related: #954275 - sssd fails connect to IPA server during boot when spanning tree is enabled in network router. - Remove enumerate=true from example in man page - Related: #988381 - clarify the disadvantages of enumeration in sssd.conf- Resolves: #914433 - sssd pam write_selinux_login_file creating the temp file for SELinux data failed- Resolves: #916997 - getgrnam / getgrgid for large user groups is too slow due to range retrieval functionality- Resolves: #918394 - sssd etas 99% CPU and runs out of file descriptors when clearing cache- Resolves: #924113 - man sssd-sudo has wrong title- Resolves: #924397 - document what does access_provider=ad do- Use permissive control when adding ghost users - Resolves: #928797 - cyclic group memberships may not work depending on order of operations- Set correct state of SRV servers on resolving error - Resolves: #954275 - sssd fails connect to IPA server during boot when spanning tree is enabled in network router.- Resolves: #954323 - SSSD doesn't display warning for last grace login.- Format patch to configure sysv script differently - RHEL-6 patch(1) apparently doesn't like the output of git format-patch -M -C and doesn't properly copy files on renames - Resolves: #971435 - Enhance sssd init script so that it would source a configuration.- Resolves: #973345 - SSSD service randomly dies- Resolves: #971435 - Enhance sssd init script so that it would source a configuration- Resolves: #961356 - SUDO is not working for users from trusted AD domain- Resolves: #970519 - [RFE] Add support for suppressing group members- Resolves: #976273 - [RFE] Add a new override_homedir expansion for the "original value"- Resolves: #978966 - sudoHost mismatch response is incorrect sometimes- Clarify the min_id/max_id limits further - Resolves: #978994 - SSSD filter out ldap user/group if uid/gid is zero- Resolves: #979046 - sssd_be goes to 99% CPU and causes significant login delays when client is under load- Resolves: #986379 - sss_cache -N/-n should invalidate the hash table in sssd_nss- Resolves: #988525 - sssd fails instead of skipping when a sudo ldap filter returns entries with multiple CNs- Mention that enumeration should be discouraged - Resolves: #988381 - clarify the disadvantages of enumeration in sssd.conf- Call restorecon on memcache files to force the right context on upgrades - Resolves: #987456 - RHEL6 sssd upgrade restorecon workaround for /var/lib/sss/mc context- Resolves: #987479 - libsss_sudo should depend on sudo package with sssd support- Resolves: #951086 - sssd_pam segfaults if sssd_be is stuck- Resolves: #967636 - SSSD frequently fails to return automount maps from LDAP- Resolves: #953165 - Enabling enumeration causes sssd_be process to utilize 100% of the CPU- Resolves: #906398 - sssd_be crashes sometimes- Resolves: #950874: Simple access control always denies uppercased users in case insensitive domain- Resolves: #921454: Resolve local group members in LDAP groups- Resolves: rhbz#911299 - sssd: simple access provider flaw prevents intended ACL use when client to an AD provider- Fix pwd_expiration_warning=0 - Resolves: rhbz#911329 - pwd_expiration_warning has wrong default for Kerberos- Resolves: rhbz#911329 - pwd_expiration_warning has wrong default for Kerberos- Resolves: rhbz#872827 - Serious performance regression in sssd- Resolves: rhbz#888614 - Failure in memberof can lead to failed database update- Resolves: rhbz#903078 - TOCTOU race conditions by copying and removing directory trees- Resolves: rhbz#903078 - Out-of-bounds read flaws in autofs and ssh services responders- Resolves: rhbz#902716 - Rule mismatch isn't noticed before smart refresh on ppc64 and s390x- Resolves: rhbz#896476 - SSSD should warn when pam_pwd_expiration_warning value is higher than passwordWarning LDAP attribute.- Resolves: rhbz#902436 - possible segfault when backend callback is removed- Resolves: rhbz#895132 - Modifications using sss_usermod tool are not reflected in memory cache- Resolves: rhbz#894302 - sssd fails to update to changes on autofs maps- Resolves: rhbz894381 - memory cache is not updated after user is deleted from ldb cache- Resolves: rhbz895615 - ipa-client-automount: autofs failed in s390x and ppc64 platform- Resolves: rhbz#894997 - sssd_be crashes looking up members with groups outside the nesting limit- Resolves: rhbz#895132 - Modifications using sss_usermod tool are not reflected in memory cache- Resolves: rhbz#894428 - wrong filter for autofs maps in sss_cache- Resolves: rhbz#894738 - Failover to ldap_chpass_backup_uri doesn't work- Resolves: rhbz#887961 - AD provider: getgrgid removes nested group memberships- Resolves: rhbz#878583 - IPA Trust does not show secondary groups for AD Users for commands like id and getent- Resolves: rhbz#874579 - sssd caching not working as expected for selinux usermap contexts- Resolves: rhbz#892197 - Incorrect principal searched for in keytab- Resolves: rhbz#891356 - Smart refresh doesn't notice "defaults" addition with OpenLDAP- Resolves: rhbz#878419 - sss_userdel doesn't remove entries from in-memory cache- Resolves: rhbz#886848 - user id lookup fails for case sensitive users using proxy provider- Resolves: rhbz#890520 - Failover to krb5_backup_kpasswd doesn't work- Resolves: rhbz#874618 - sss_cache: fqdn not accepted- Resolves: rhbz#889182 - crash in memory cache- Resolves: rhbz#889168 - krb5 ticket renewal does not read the renewable tickets from cache- Resolves: rhbz#886091 - Disallow root SSH public key authentication - Add default section to switch statement (Related: rhbz#884666)- Resolves: rhbz#886038 - sssd components seem to mishandle sighup- Resolves: rhbz#888800 - Memory leak in new memcache initgr cleanup function- Resolves: rhbz#888614 - Failure in memberof can lead to failed database update- Resolves: rhbz#885078 - sssd_nss crashes during enumeration if the enumeration is taking too long- Related: rhbz#875851 - sysdb upgrade failed converting db to 0.11 - Include more debugging during the sysdb upgrade- Resolves: rhbz#877972 - ldap_sasl_authid no longer accepts full principal- Resolves: rhbz#870045 - always reread the master map from LDAP - Resolves: rhbz#876531 - sss_cache does not work for automount maps- Resolves: rhbz#884666 - sudo: if first full refresh fails, schedule another first full refresh- Resolves: rhbz#880956 - Primary server status is not always reset after failover to backup server happened - Silence a compilation warning in the memberof plugin (Related: rhbz#877974) - Do not steal resolv result on error (Related: rhbz#882076)- Resolves: rhbz#882923 - Negative cache timeout is not working for proxy provider- Resolves: rhbz#884600 - ldap_chpass_uri failover fails on using same hostname- Resolves: rhbz#858345 - pam_sss(crond:account): Request to sssd failed. Timer expired- Resolves: rhbz#878419 - sss_userdel doesn't remove entries from in-memory cache- Resolves: rhbz#880176 - memberUid required for primary groups to match sudo rule- Resolves: rhbz#885105 - sudo denies access with disabled ldap_sudo_use_host_filter- Resolves: rhbz#883408 - Option ldap_sudo_include_regexp named incorrectly- Resolves: rhbz#880546 - krb5_kpasswd failover doesn't work - Fix the error handler in sss_mc_create_file (Related: #789507)- Resolves: rhbz#882221 - Offline sudo denies access with expired entry_cache_timeout - Fix several bugs found by Coverity and clang: - Check the return value of diff_gid_lists (Related: #869071) - Move misplaced sysdb assignment (Related: #827606) - Remove dead assignment (Related: #827606) - Fix copy-n-paste error in the memberof plugin (Related: #877974)- Resolves: rhbz#882923 - Negative cache timeout is not working for proxy provider - Link sss_ssh_authorizedkeys and sss_ssh_knowhostsproxy with the client libraries (Related: #870060) - Move sss_ssh_knownhosts documentation to the correct section (Related: #870060)- Resolves: rhbz#884480 - user is not removed from group membership during initgroups - Fix incorrect synchronization in mmap cache (Related: #789507)- Resolves: rhbz#883336 - sssd crashes during start if id_provider is not mentioned- Resolves: rhbz#882290 - arithmetic bug in the SSSD causes netgroup midpoint refresh to be always set to 10 seconds- Resolves: rhbz#877974 - updating top-level group does not reflect ghost members correctly - Resolves: rhbz#880159 - delete operation is not implemented for ghost users- Resolves: rhbz#881773 - mmap cache needs update after db changes- Resolves: rhbz#875677 - password expiry warning message doesn't appear during auth - Fix potential NULL dereference when skipping built-in AD groups (Related: rhbz#874616) - Add missing parameter to DEBUG message (Related: rhbz#829742)- Resolves: rhbz#882076 - SSSD crashes when c-ares returns success but an empty hostent during the DNS update - Do not version libsss_sudo, it's not supposed to be linked against, but dlopened (Related: rhbz#761573)- Resolves: rhbz#880140 - sssd hangs at startup with broken configurations- Resolves: rhbz#878420 - SIGSEGV in IPA provider when ldap_sasl_authid is not set- Resolves: rhbz#874616 - Silence the DEBUG messages when ID mapping code skips a built-in group- Resolves: rhbz#824244 - sssd does not warn into sssd.log for broken configurations- Resolves: rhbz#874673 - user id lookup fails using proxy provider - Fix a possibly uninitialized variable in the LDAP provider - Related: rhbz#877130- Resolves: rhbz#878262 - ipa password auth failing for user principal name when shorter than IPA Realm name - Resolves: rhbz#871843 - Nested groups are not retrieved appropriately from cache- Resolves: rhbz#870238 - IPA client cannot change AD Trusted User password- Resolves: rhbz#877972 - ldap_sasl_authid no longer accepts full principal- Resolves: rhbz#861075 - SSSD_NSS failure to gracefully restart after sbus failure- Resolves: rhbz#877354 - ldap_connection_expire_timeout doesn't expire ldap connections- Related: rhbz#877126 - Bump the release tag- Resolves: rhbz#877126 - subdomains code does not save the proper user/group name- Resolves: rhbz#877130 - LDAP provider fails to save empty groups - Related: rhbz#869466 - check the return value of waitpid()- Resolves: rhbz#870039 - sss_cache says 'Wrong DB version'- Resolves: rhbz#875740 - "defaults" entry ignored- Resolves: rhbz#875738 - offline authentication failure always returns System Error- Resolves: rhbz#875851 - sysdb upgrade failed converting db to 0.11- Resolves: rhbz#870278 - ipa client setup should configure host properly in a trust is in place- Resolves: rhbz#871160 - sudo failing for ad trusted user in IPA environment- Resolves: rhbz#870278 - ipa client setup should configure host properly in a trust is in place- Resolves: rhbz#869678 - sssd not granting access for AD trusted user in HBAC rule- Resolves: rhbz#872180 - subdomains: Invalid sub-domain request type - Related: rhbz#867933 - invalidating the memcache with sss_cache doesn't work if the sssd is not running- Resolves: rhbz#873988 - Man page issue to list 'force_timeout' as an option for the [sssd] section- Resolves: rhbz#873032 - Move sss_cache to the main subpackage- Resolves: rhbz#873032 - Move sss_cache to the main subpackage - Resolves: rhbz#829740 - Init script reports complete before sssd is actually working - Resolves: rhbz#869466 - SSSD starts multiple processes due to syntax error in ldap_uri - Resolves: rhbz#870505 - sss_cache: Multiple domains not handled properly - Resolves: rhbz#867933 - invalidating the memcache with sss_cache doesn't work if the sssd is not running - Resolves: rhbz#872110 - User appears twice on looking up a nested group- Resolves: rhbz#871576 - sssd does not resolve group names from AD - Resolves: rhbz#872324 - pam: fd leak when writing the selinux login file in the pam responder - Resolves: rhbz#871424 - authconfig chokes on sssd.conf with chpass_provider directive- Do not send SIGKILL to service right after sending SIGTERM - Resolves: #771975 - Fix the initial sudo smart refresh - Resolves: #869013 - Implement password authentication for users from trusted domains - Resolves: #869071 - LDAP child crashed with a wrong keytab - Resolves: #869150 - The sssd_nss process grows the memory consumption over time - Resolves: #869443- BuildRequire selinux-policy so that selinux login support is built in - Resolves: #867932- Do not segfault if namingContexts contain no values or multiple values - Resolves: rhbz#866542- Fix the "ca" translation of the sssd-simple manual page - Related: rhbz#827606 - Rebase SSSD to 1.9 in 6.4- New upstream release 1.9.2- Rebase to 1.9.1- Require the latest libldb- Rebase to 1.9.0 - Resolves: rhbz#827606 - Rebase SSSD to 1.9 in 6.4- Rebase to 1.9.0 RC1 - Resolves: rhbz#827606 - Rebase SSSD to 1.9 in 6.4 - Bump the selinux-policy version number to pull in required fixes- Resolves: rhbz#840089 - Update the shadowLastChange attribute with days since the Epoch, not seconds- Fix protocol break for services map - Related: rhbz#825028 - Service lookups by port number doesn't work on s390x/ppc64 arches- Resolves: rhbz#825028 - Service lookups by port number doesn't work on s390x/ppc64 arches- Resolves: rhbz#824616 - sssd_nss crashes when configured with use_fully_qualified_names = true- Resolves: rhbz#824062 - sssd_be crashed with SIGSEGV in _tevent_schedule_immediate()- Resolves: rhbz#822236 - SSSD netgroups do not honor entry_cache_nowait_percentage- Resolves: rhbz#820759 - AVC denial seen on sssd upgrade during ipa-client upgrade - Resolves: rhbz#821044 - sss_groupadd no longer detects duplicate GID numbers- Resolves: rhbz#818642 - Auth fails for user with non-default attribute names - Resolves: rhbz#819063 - sssd fails to provide partial data till paged search returns "Size Limit Exceeded" - Resolves: rhbz#820585 - Group enumeration fails in proxy provider- Resolves: rhbz#816616 - group members are now lowercased in case insensitive domains- Resolves: rhbz#805431 - NFS files/folders are mapped to nobody user if NFS top level directory is chowned by a SSSD user- Resolves: rhbz#805924 - SSSD should attempt to get the RootDSE after binding - Resolves: rhbz#814237 - sdap_check_aliases must not error when detects the same user - Resolves: rhbz#812281 - autofs client: map name length used as key length - Related: rhbz#784870 - SSSD fails during autodetection of search bases for new LDAP features - Related: rhbz#814269 - sssd-1.5.1-66.el6_2.3.x86_64 freezes- Fix typo in patch for SSH umask - Related: rhbz#808107 - Coverity revealed memory management defects- Resolves: rhbz#808458 - Authconfig crashes when sets krb realm - Resolves: rhbz#808597 - sssd_nss crashes on request when no back end is running - Resolves: rhbz#808107 - Coverity revealed memory management defects- Related: rhbz#805452 - Unable to lookup user, group, netgroup aliases with case_sensitive=false- Resolves: rhbz#804057 - Initial service lookups having name with uppercase alphabets doesn't work - Resolves: rhbz#804065 - Service lookup using case-sensitive protocol names doesn't work when case_sensitive=false - Resolves: rhbz#805281 - sssd: Uses the wrong key when there a multiple realms in a single keytab - Resolves: rhbz#805452 - Unable to lookup user, group, netgroup aliases with case_sensitive=false - Resolves: rhbz#805918 - Wrong resolv_status might cause crash when name resolution times out - Resolves: rhbz#805431 - NFS files/folders are mapped to nobody user if NFS top level directory is chowned by a SSSD user- Related: rhbz#802207 - getent netgroup hangs when "use_fully_qualified_names = TRUE" in sssd - Resolves: rhbz#801719 - "Error looking up public keys" while ssh to replica using IP address - Resolves: rhbz#803659 - Service lookup shows case sensitive names twice with case_sensitive=false - Resolves: rhbz#803842 - Unable to bind to LDAP server when minssf set - Resolves: rhbz#805034 - accessing an undefined variable might cause crash - Resolves: rhbz#805108 - sss_ssh_knownhostproxy infinite loop hangs SSH login- Update translations - Resolves: rhbz#802372 - Pick up latest translation files for SSSD - Resolves: rhbz#802207 - getent netgroup hangs when "use_fully_qualified_names = TRUE" in sssd - Related: rhbz#801451 - Logging in with ssh pub key should consult authentication authority policies- Resolves: rhbz#801407 - sssd_nss gets hung processing identical search requests - Resolves: rhbz#801451 - Logging in with ssh pub key should consult authentication authority policies - Resolves: rhbz#795562 - Infinite loop checking Kerberos credentials - Resolves: rhbz#798317 - sssd crashes when ipa_hbac_support_srchost is set to true - Resolves: rhbz#799039 - --debug option for sss_debuglevel doesn't work - Resolves: rhbz#799915 - Unable to lookup netgroups with case_sensitive=false - Resolves: rhbz#799929 - Raise limits for max num of files sssd_nss/sssd_pam can use - Resolves: rhbz#799971 - sssd_be crashes on shutdown - Resolves: rhbz#801533 - sssd_be crashes when resolving non-trivial nested group structure - Resolves: rhbz#801368 - Group lookups doesn't return members with proxy provider configured - Resolves: rhbz#801377 - getent returns non-existing netgroup name, when sssd is configured as proxy provider- Do not auto-upgrade debug levels - Tool still available for manual use - Reverts: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade - Resolves: rhbz#798881 - Install-time warnings - Resolves: rhbz#798774 - IPA provider should assume that ipa_domain is also the dns_discovery_domain - Resolves: rhbz#798655 - Password logins failing due to a process with high UID- Fix explicit requires to use openldap instead of openldap-libs - Related: rhbz#797282 - sssd-1.5.1-66.el6.x86_64 needs openldap >= openldap-2.4.23-20.el6.x86_64- Fix multilib-clean issue due to upgrade script - Remove old copy from the spec file - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Fix typo in the patch - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Use a patch and install the script to python_sitelib - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Resolves: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade - Resolves: rhbz#785871 - wrong build dependency on nscd - Resolves: rhbz#785873 - IPA host search base cannot be set - Resolves: rhbz#791208 - Entries lacking a POSIX username value break group lookups - Resolves: rhbz#796307 - Simple Paged Search control needs to be used more sparingly - Resolves: rhbz#797282 - sssd-1.5.1-66.el6.x86_64 needs openldap >= openldap-2.4.23-20.el6.x86_64 - Resolves: rhbz#787035 - ipa - sssd slow response with thousands of user entries - Resolves: rhbz#742509 - [RFE] Add SSSD Tool to purge cache - Resolves: rhbz#772297 - Fails to update if all nisNetgroupTriple or memberNisNetgroup entries are deleted from a netgroup - Resolves: rhbz#783138 - Backend occasionally goes offline under heavy load - Resolves: rhbz#797975 - sssd_be: The requested target is not configured is logged at each login - Resolves: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3- Resolves: rhbz#761570 - [RFE] support looking up autofs maps via SSSD - Resolves: rhbz#788979 - sssd crashes during initgroups against a user belonging to nested rfc2307bis group- Handle filtering python Provides in a safer way - Related: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3- Related: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3 - Resolves: rhbz#786553 - sssd on ppc64 doesn't pull cyrus-sasl-gssapi.ppc as a dependancy - Resolves: rhbz#785909 - --debug-timestamps=1 is not passed to providers - Resolves: rhbz#785908 - ldap_*_search_base doesn't fully limit the group and netgroup search base correctly - Resolves: rhbz#785907 - [RFE] Add support to request canonicalization on krb AS requests - Resolves: rhbz#785905 - [RFE] DEBUG timestamps should offer higher precision - Resolves: rhbz#785904 - [RFE] SSSD should have --version option - Resolves: rhbz#785902 - Errors with empty loginShell and proxy provider - Resolves: rhbz#785898 - Enable midway cache refresh by default - Resolves: rhbz#785888 - sssd returns empty netgroup at a second request for a non-existing netgroup - Resolves: rhbz#785884 - Honour TTL when resolving host names - Resolves: rhbz#785883 - check DNS records before updates - Resolves: rhbz#785881 - List the keytab to pick the princiapl to use instead of guessing - Resolves: rhbz#785880 - debug_level in sssd.conf overrides command-line - Resolves: rhbz#785879 - sss_obfuscate/python config parser modifies config file too much - Resolves: rhbz#785877 - on reconnect we need to detect that a ipa/ds server has been reinitialized - Resolves: rhbz#785741 - sssd.api.conf and sssd.api.d should not be in /etc - Resolves: rhbz#773660 - Kerberos errors should go to syslog - Resolves: rhbz#772163 - Iterator loop reuse cases a tight loop in the native IPA netgroups code - Resolves: rhbz#771706 - sssd_be crashes during auth when there exists UTF source host group in an hbacrule - Resolves: rhbz#771702 - sssd_pam crashes during change password operation against a IPA server - Resolves: rhbz#771361 - case_sensitive function not working as intended for ldap - Resolves: rhbz#768935 - Crash when applying settings - Resolves: rhbz#766941 - The full dyndns update message should be logged into debug logs - Resolves: rhbz#766930 - [RFE] Add a new option to override home directory value - Resolves: rhbz#766913 - [RFE] Add option to select validate and FAST keytab principal name - Resolves: rhbz#766907 - Use [...] for IPv6 addresses in kdc info files - Resolves: rhbz#766904 - [RFE] Create a command line tool to change the debug levels on the fly - Resolves: rhbz#766876 - [RFE] Make HBAC srchost processing optional - Resolves: rhbz#766141 - [RFE] SSSD should support FreeIPA's internal netgroup representation - Resolves: rhbz#761582 - [RFE] Add ldap_sasl_minssf option - Resolves: rhbz#759186 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#755506 - [RFE] Add host-based (pam_host_attr) access control - Resolves: rhbz#753876 - [RFE] Add support for the services map - Resolves: rhbz#746181 - "getgrgid call returned more than one result" after group name change in MSAD - Resolves: rhbz#744197 - [RFE] close LDAP connection to the server when idle for some (configurable) time - Resolves: rhbz#742510 - [RFE] Separate Cache Timeouts for SSSD - Related: rhbz#742509 - [RFE] Add SSSD Tool to purge cache - Resolves: rhbz#742052 - id -G group resolution takes extremely long - Resolves: rhbz#739312 - [RFE] sssd does not set shadowLastChange - Resolves: rhbz#736150 - [RFE] SSSD should support multiple search bases - Resolves: rhbz#735827 - [RFE] Ability to set a domain as case sensitive or insensitive - Resolves: rhbz#735405 - [RFE] Option to disable warnings for unknown users - Resolves: rhbz#728212 - [RFE] sssd does not handle when paging control disabled for openldap - Resolves: rhbz#726467 - SSSD takes 30+ seconds to login - Resolves: rhbz#721289 - Process /usr/libexec/sssd/sssd_be was killed by signal 11 during auth when password for the user is not set- Resolves: rhbz#773655 - Race-condition bug in LDAP auth provider- Resolves: rhbz#753842 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758157 - LDAP failover not working if server refuses connections- Related: rhbz#750359 - Major cached entry performance regression- Resolves: rhbz#750359 - Major cached entry performance regression- Resolves: rhbz#749822 - SSSD may go into infinite loop during RFC2307bis initgroups when groups appear in multiple nesting levels- Resolves: rhbz#749256 - SELinux errors with SSSD Downgrade- Resolves: rhbz#748924 - RHEL6.1/sssd_pam segmentation fault- Resolves: rhbz#748412 - Memory leaks during the initgroups() operation- Related: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#742288 - RFC2307bis initgroups calls are slow - Resolves: rhbz#746654 - SSSD backend gets killed on slow systems - Related: rhbz#743925 - HBAC processing is very slow when dealing with FreeIPA deployments with large numbers of hosts Fixes a crash introduced by the earlier patch. - Related: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names Fixes for internationalization- Related: rhbz#742278 - Rework the example config- Resolves: rhbz#743925 - HBAC processing is very slow when dealing with FreeIPA deployments with large numbers of hosts - Resolves: rhbz#745966 - sssd_pam segfaults on sssd restart - Related: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#742278 - Rework the example config - Resolves: rhbz#746037 - Only access sssd_nss internal hash table if it was initialized - Resolves: rhbz#742526 - SSSD's man pages are missing information - Resolves: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#738621 - Lookup fails for non-primary usernames with multi-valued uid - Resolves: rhbz#738629 - Group lookups doesn't return it's member for sometime when the member has multi-valued uid - Resolves: rhbz#742295 - Use an explicit base 10 when converting uidNumber to integer - Resolves: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names- Resolves: rhbz#741751 - HBAC rule evaluation does not properly handle host groups - Resolves: rhbz#740501 - SSSD not functional after "self" reboot - Resolves: rhbz#742539 - HBAC: Hostname comparisons should be case-insensitive- Resolves: rhbz#728343 - SSSD taking 5 minutes to log in - Resolves: rhbz#739850 - Coverity defects newly introduced in rhel 6.2- Resolves: rhbz#737157 - "System error" appears in log during change password operation of a user in openldap server with ppolicy enabled - Resolves: rhbz#737172 - "Unknown (private extension) error(21853), (null)" messages are logged during change password operation of a user in openldap server with ppolicy enabled- Resolves: rhbz#736314 - sssd crashes during auth while there exists multiple external hosts along with managed host - Resolves: rhbz#732974 - [RFE] Have SSSD cache properly with krb5_validate = True and SElinux enabled- Resolves: rhbz#732010 - LDAP+GSSAPI needs explicit Kerberos realm - Resolves: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names - Resolves: rhbz#733409 - Improve password policy error message - Resolves: rhbz#733663 - Authentication fails when there exists an empty hbacsvcgroup - Resolves: rhbz#732935 - Add LDAP provider option to set LDAP_OPT_X_SASL_NOCANON - Resolves: rhbz#734101 - sssd blocks login of ipa-users- Related: rhbz#728353 - Resolve RPMDiff errors in SSSD- Resolves: rhbz#728961 - Provide a mechanism for vetoing the use of certain shells- Related: rhbz#728267 - When non-posix groups are skipped, initgroups returns random GID- Related: rhbz#726466 - HBAC rule evaluation does not support extended UTF-8 languages - Related: rhbz#718250 - Remove DENY rules from the HBAC access provider - Fixes an issue on big endian platforms- Resolves: rhbz#700828 - Process /usr/libexec/sssd/sssd_be was killed by signal 11 (SIGSEGV) when ldap_uri is misconfigured - Resolves: rhbz#726438 - sssd doesn't honor ldap supportedControls - Resolves: rhbz#726466 - HBAC rule evaluation does not support extended UTF-8 languages - Resolves: rhbz#718250 - Remove DENY rules from the HBAC access provider - Resolves: rhbz#728267 - When non-posix groups are skipped, initgroups returns random GID - Resolves: rhbz#726475 - sssd_pam leaks file descriptors - Resolves: rhbz#725868 - Explicitly ignore groups with gidNumber = 0- Related: rhbz#721052 - sssd does not handle kerberos server IP change - Use ares_search instead of ares_query to honor - search entries in /etc/resolv.conf- Resolves: rhbz#711416 - During the change password operation the ccache is - not replaced by a new one if the old one isn't - active anymore - Resolves: rhbz#715609 - Certificate validation fails with message - "Connection error: TLS: hostname does not match CN - in peer certificate" - Resolves: rhbz#719089 - IPA dynamic DNS update mangles AAAA records - Resolves: rhbz#721052 - sssd does not handle kerberos server IP change - Honor TTL values when resolving hostnames- Resolves: rhbz#713961 - libsss_ldap segfault at login against OpenLDAP - Resolves: rhbz#713438 - sssd shuts down if inotify crashes- Resolves: rhbz#709081 - sssd.$arch should require sssd-client.$arch- Resolves: rhbz#709342 - Typo in negative cache notification for initgroups() - Resolves: rhbz#708009 - "renew_all_tgts" and "renew_handlers" messages are - being logged multiple times when the provider comes - back online - Resolves: rhbz#707997 - The IPA provider does not work with IPv6 - Resolves: rhbz#677327 - [RFE] Support overriding attribute value - Resolves: rhbz#692090 - SSSD is not populating nested groups in - Active Directory- Resolves: rhbz#707627 - Include valid "ldap_uri" formats in sssd-ldap man - page- Resolves: rhbz#707513 - Unable to authenticate users when username - contains "\0"- Resolves: rhbz#698723 - kpasswd fails when using sssd and - kadmin server != kdc server- Resolves: rhbz#707282 - latest sssd fails if ldap_default_authtok_type is - not mentioned - Resolves: rhbz#692404 - rfc2307bis groups are being enumerated even when the - gidNumber is out of the range of min_id,max_id. - Resolves: rhbz#699530 - Users with a local group as their primary GID are - denied access by the simple access provider - Resolves: rhbz#700172 - RFE: SSSD should support paged LDAP lookups - Resolves: rhbz#705434 - IPA provider fails initgroups() if user is not a - member of any group - Resolves: rhbz#703624 - SSSD's async resolver only tries the first - nameserver in /etc/resolv.conf- Resolves: rhbz#701700 - sssd client libraries use select() but should use - poll() instead- Related: rhbz#693818 - Automatic TGT renewal overwrites cached password - Fix segfault in TGT renewal- Related: rhbz#693818 - Automatic TGT renewal overwrites cached password - Fix typo causing build breakage- Resolves: rhbz#693818 - Automatic TGT renewal overwrites cached password- Resolves: rhbz#696972 - Filters not honoured against fully-qualified users- Resolves: rhbz#694146 - SSSD consumes GBs of RAM, possible memory leak- Related: rhbz#691678 - SSSD needs to fall back to 'cn' for GECOS - information- Related: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#694444 - Unable to resolve SRV record when called with - _srv_, in ldap_uri - Related: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#692472 - Process /usr/libexec/sssd/sssd_be was killed by - signal 11 (SIGSEGV) - Fix is to not attempt to resolve nameless servers- Resolves: rhbz#691678 - SSSD needs to fall back to 'cn' for GECOS - information- Resolves: rhbz#690866 - Groups with a zero-length memberuid attribute can - cause SSSD to stop caching and responding to - requests- Resolves: rhbz#690131 - Traceback messages seen while interrupting - sss_obfuscate using ctrl+d - Resolves: rhbz#690421 - [abrt] sssd-1.2.1-28.el6_0.4: _talloc_free: Process - /usr/libexec/sssd/sssd_be was killed by signal 11 - (SIGSEGV)- Related: rhbz#683885 - SSSD should skip over groups with multiple names- Resolves: rhbz#683158 - SSSD breaks on RDNs with a comma in them - Resolves: rhbz#689886 - group memberships are not populated correctly during - IPA provider initgroups - Resolves: rhbz#683885 - SSSD should skip over groups with multiple names- Resolves: rhbz#683860 - Skip users and groups that have incomplete contents - Resolves: rhbz#688491 - authconfig fails when access_provider is set as krb5 - in sssd.conf- Resolves: rhbz#683255 - sudo/ldap lookup via sssd gets stuck for 5min - waiting on netgroup - Resolves: rhbz#683431 - sssd consumes 100% CPU - Related: rhbz#680440 - sssd does not handle kerberos server IP change- Related: rhbz#680440 - sssd does not handle kerberos server IP change - SSSD was staying with the old server if it was still online- Resolves: rhbz#682850 - IPA provider should use realm instead of ipa_domain - for base DN- Resolves: rhbz#682340 - sssd-be segmentation fault - ipa-client on - ipa-server - Resolves: rhbz#680440 - sssd does not handle kerberos server IP change - Resolves: rhbz#680442 - Dynamic DNS update fails if multiple servers are - given in ipa_server config option - Resolves: rhbz#680932 - Do not delete sysdb memberOf if there is no memberOf - attribute on the server - Resolves: rhbz#682807 - sssd_nss core dumps with certain lookups- Related: rhbz#678614 - SSSD needs to look at IPA's compat tree for netgroups - Related: rhbz#679082 - SSSD IPA provider should honor the krb5_realm option- Resolves: rhbz#679082 - SSSD IPA provider should honor the krb5_realm option - Resolves: rhbz#677318 - Does not read renewable ccache at startup- Resolves: rhbz#678593 - User information not updated on login for secondary - domains - Resolves: rhbz#678777 - IPA provider does not update removed group - memberships on initgroups- Resolves: rhbz#677588 - sssd crashes at the next tgt renewals it tries - Resolves: rhbz#678410 - name service caches names, so id command shows - recently deleted users - Resolves: rhbz#678614 - SSSD needs to look at IPA's compat tree for - netgroups- Resolves: rhbz#670511 - SSSD and sftp-only jailed users with pubkey login - Resolves: rhbz#675284 - "no matching rule" message logged on all successful - requests - Resolves: rhbz#676911 - SSSD attempts to use START_TLS over LDAPS for - authentication- Resolves: rhbz#674164 - sss_obfuscate fails if there's no domain named - "default" - Resolves: rhbz#674515 - -p option always uses empty string to obfuscate - password - Resolves: rhbz#674141 - Traceback call messages displayed while - "sss_obfuscate" command is executed as a non-root - user- Resolves: rhbz#674172 - Group members are not sanitized in nested group - processing - Put translated tool manpages into the sssd-tools subpackage- Related: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - Also add the updated ding-libs to the BuildRequires- Related: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - Explicitly require updated ding-libs- Resolves: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options - Assorted bugfixes- Add noverify to sssd.conf - Resolves: rhbz#627165 - TPS VerifyTest failure- Related: rhbz#644072 - Rebase SSSD to 1.5 - New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Resolves: rhbz#660592 - SSSD shutdown sometimes hangs - Resolves: rhbz#660585 - getent passwd ' returns nothing if its - uidNumber gt 2147483647- Resolves: rhbz#659401 - SSSD shutdown sometimes hangs- Resolves: rhbz#645449 - 'getent passwd ' returns nothing if its - uidNumber gt 2147483647- Resolves: rhbz#658374 - sssd stops on upgrade- Resolves: rhbz#658158 - sssd stops on upgrade- Resolves: rhbz#649312 - SSSD will sometimes lose groups from the cache- Resolves: rhbz#649286 - SSSD will sometimes lose groups from the cache- Resolves: rhbz#637070 - the krb5 locator plugin isn't packaged for multilib - Resolves: rhbz#642412 - SSSD initgroups does not behave as expected- Resolves: rhbz#633406 - the krb5 locator plugin isn't packaged for multilib - Resolves: rhbz#633487 - SSSD initgroups does not behave as expected- Resolves: rhbz#633406 - the krb5 locator plugin isn't packaged for multilib- Resolves: rhbz#629949 - sssd stops on upgrade- Resolves: rhbz#625122 - GNOME Lock Screen unocks without a password- Resolves: rhbz#621307 - Password changes are broken on LDAP- Resolves: rhbz#617623 - SSSD suffers from serious performance issues on - initgroups calls- Resolves: rhbz#607233 - SSSD users cannot log in through GDM - - Real issue was that long-running services - - do not reconnect if sssd is restarted- Resolves: rhbz#591715 - sssd should emit warnings if there are problems with - /etc/krb5.keytab file- Resolves: rhbz#606836 - libcollection needs an soname bump before RHEL 6 - final - Resolves: rhbz#608661 - SASL with OpenLDAP server fails - Resolves: rhbz#608688 - SSSD doesn't properly request RootDSE attributes- New upstream bugfix release 1.2.1 - Resolves: rhbz#601770 - SSSD in RHEL 6.0 should ship with zero open Coverity - bugs. - Resolves: rhbz#603041 - Remove unnecessary option krb5_changepw_principal - Resolves: rhbz#604704 - authconfig should provide error with no trace back - if disabling sssd when sssd is not enabled - Resolves: rhbz#591873 - Connecting to the network after an offline kerberos - auth logs continuous error messages to sssd_ldap.log - Resolves: rhbz#596295 - Authentication fails for user from the second domain - when the same user name is filtered out from the - first domain - Related: rhbz#598559 - Update translation files for SSSD before RHEL 6 - final- Resolves: rhbz#593696 - Empty list of simple_allow_users causes sssd service - to fail while restart - Resolves: rhbz#600352 - Wrapping the value for "ldap_access_filter" in - parentheses causes ldap_search_ext to fail - Resolves: rhbz#600468 - Segfault in krb5_child - Related: rhbz#601770 - SSSD in RHEL 6.0 should ship with zero open Coverity - bugs.- Resolves: rhbz#598670 - Ccache file of a user is removed too early - Resolves: rhbz#599057 - Incomplete comparison of a service name in - IPA access provider - Resolves: rhbz#598496 - Failure with IPA access provider - Resolves: rhbz#599027 - Makefile typo causes SSSD not to use the - kernel keyring- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP - Resolves: rhbz#584001 - Rebase sssd to 1.2 - Resolves: rhbz#584017 - Unconfiguring sssd leaves KDC locator file - Resolves: rhbz#587384 - authconfig fails if krb5_kpasswd in sssd.conf - Resolves: rhbz#587743 - Need to replicate pam_ldap's pam_filter in sssd.conf - Resolves: rhbz#590134 - sssd: auth_provider = proxy regression - Resolves: rhbz#591131 - Kerberos provider needs to rewrite kdcinfo file when - going online - Resolves: rhbz#591136 - Change SSSD ipa BE to handle new structure of the - HBAC rule- Improve DEBUG logs for STARTTLS failures- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcacacacacacacacacacacacsdedededededededededededeesesesesesesesesesesesfrfrfrfrfrfrfrfrfrfrfrfrjajajajajajajajajajajanlptptukukukukukukukukukukukukuk1.13.3-60.el61.13.3-60.el6 sss_debuglevelsss_groupaddsss_groupdelsss_groupmodsss_groupshowsss_obfuscatesss_overridesss_seedsss_useraddsss_userdelsss_usermodsssd-tools-1.13.3COPYINGsss_rpcidmapd.5.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_groupdel.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_override.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_groupmod.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_rpcidmapd.5.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gz/usr/sbin//usr/share/doc//usr/share/doc/sssd-tools-1.13.3//usr/share/man/ca/man5//usr/share/man/ca/man8//usr/share/man/cs/man8//usr/share/man/de/man1//usr/share/man/de/man8//usr/share/man/es/man1//usr/share/man/es/man8//usr/share/man/fr/man1//usr/share/man/fr/man8//usr/share/man/ja/man1//usr/share/man/ja/man8//usr/share/man/man8//usr/share/man/nl/man8//usr/share/man/pt/man8//usr/share/man/uk/man1//usr/share/man/uk/man5//usr/share/man/uk/man8/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector --param=ssp-buffer-size=4 -m32 -march=i686 -mtune=atom -fasynchronous-unwind-tablesdrpmxz2i686-redhat-linux-gnu?7zXZ !PH6EH]"k%}:w{!vQ_99g4ڤ 4Й1Z55~ sT́Tra8}t(p'QXyrjtĘ3{`]aihY}>m* >iX;9qbGCb9Y,`)LfX1!8;n$,@a/[w6 .-2Y6=fM1:&#>7nt0{2Džn2d$0%KK;8c qn=W@`IAvoY 0Y58$9+vRZo1k~%NkFzZxgPJʬbmu/?>*qi~vjs+[;S0mv"_V߅Fh G)`*MT]O=[FyQv *AeF#3FQP?FZlS+@,tοZ?:Xyn1ooFdl^֠/|i"p~jN{?y&"";QVQ}I)˄7. ng,x%^[Y@2/{[p:bap̜0Rl@;nl}4g`~=PX"f1SA;,g[q XP )d 8o>47<8aI⯺yC#)dznS[y]]C'2H6c{ꕬgǮQuDe cŪ儾O !e9oŞ0VXIGb".##t#td4yl)Jv(a[yը]ygYy#C.Bcps{Z˰*t⾠Yqwa>K|O&[]ƀz(\ru:.8g*"gMFB E@ɥK1\jE8.98/!ꇱ`ЋFE6$Lo6wS)%gPG5Yq]xkzFh*c5/bNzb`HV:E"p6 'pC䋊H&zA%|.UOmۧܩ{)Q:?MxDZnl2vj-ZI'Gl#y_P-6uUcG d5<$dKvWmݓ袪1 {3JzQx!HZܶ!W?¦h>&ecC(:XT〒W[d(!6ʶ#>{ Qa)\ꧮEBU{ym = (U;tKyb܎o@dx>Q E%cZdEhR *T6M@=rR3!ęp!2iV?)c< 7󕪵$E#bq!K9X/*gNb>#Lvߞq\vH0ݠ iuikI`S>rq+ږ.-2^b+*^}'ci!"*ox}9)dp0E2Qn`t$bٮA$oT8"ڕ9'@ ?Z32(f@w?Ί.\y_=gS `N_d| ]%5j#ȇp0F\ך ɶ̵Rq,-`GCr&MR1bdqehVi)˞Xh)6/ V",EP3 /+D1pjO6qhEjwahP岮 &@$u &%F҆>ězA][z~WCEl p\ ص4wOW;GF[|Ӻ=%5hZ'à\ǰ+ux 9 *褧',9@(*D; U$+{tx%,ge*WU,gH\6_06(;W&4D hemW,, Q9J!\u*yqPYk. 6^oq skQKRFQ☕|q$3y-8xG= 7ڶdE;pH!V *kc¾QEGBC5zL@?y To9ڛiFwoe=KUY p#teU/i eq}xSpYJA8{Ya{m)~"BxGglc&yf3_SGq]1ZVʹcV2$H|P}!jti}L՜̣]="Rn񸱜MmC=?{3 ೓5L"fPSLp~w}q#,FCAd!o2]։>@3jtuGTC(]GjǗʱT"8x/Mn re(DwA^(o`q}SYmhAjGۨ E&byv7B}{y\_98~w6tqnqo$kpb  =^Ϭ+ǦM6o#0^KBcs6b#D.,=lZ\vAJG3}MhSY[=c7߂dSOSHNc^eaѐeU=/7i75Uh ێ.LF+m{I~`>)2}~pp(EbƳ0GL7D,Kd]WN诙 J6T[Qz`}Rj.j)q1 SpqܡXͪ/d:._f,͹mL+lwX2}KKF Fhb3)GcXK1ղpѴ,Z|3:͋/䬐bXL 8FX=OTp1ORM7sS7嶺}7R7XU8qybpO4҉|&O»aaw`4&~g"= DeF*|Do/Bk'< /h SVwkA \'9{)ّ i>ItdW\c юN;PR$CŒ'XY-g^6yc.кVEadcs;BCBMgy'HDCmJ)){# }]olDrP&rEWQaP̧t 2^bQP"qrBlUu*ľrf=8}0TՄ)B 2e3T[=bofƊ"xmZo,\\I1^_iG#w H:gzqq7+rwJjb> M=[H6ٖ)SM y2:M"ZԳﻗS zF5}|34|TPׇCqD'j~>N(jmd4< ||${<1c;4G~˹ %5,ݑo_\ȂV>S5%v @()Bըa)"A GDT%:|P"M^솖wdfgEyPsH NJ4(H 蹬3Kzh1X$m˥ј3vC]гLw 'CCMM X3)135v⛅fLO){/{KyKE+RGm;FDvlGRčMNOp#QJ\+}}?̐.|j/g\$-EWL)ř8QdR׼ODWY{{,i&7zQʈt, 757.іt}:3\ƋG34iĜ@<͹yg+b6ztHԅCGygfrh6.(JMSYWth4JlNHTC:SeHfR1|,wQDB&c}#bMo1~R,-avh. 0"LDmq>@&GC8<`Ę9`qDڔcP0@kUNw`N9O&&i1%g՘ SX7#m]tx95NF9"QPt? Zh'ik:̟N Y &ql\}V{%B' +\L#3} ]޹jF`DrU3z!Cٞ9m -`a4;P9-@tI;K"-A/z:ywř+bhc&՛ӣWBOM{U@ZAښ19PdT!`Ufxè'\8x~ʗ k Y+1R5k7Q,[}o ZW q8¬!jy9^S&k֓X wɒl$˷JniMn ϊ]E^͵z܅rM|КhD$փ%QpN>@d_t\(:prq$*LQuޞyb&_ŞsgVyeuiԆ+zhiw΢8;HXOH!ɾ:~q,R->{bk@"rY!߳Tw) 6:kAӷ,\X.$ٻ |ɀeHdt{nO/#($0) `R2-n{3jCg>&|35ϾV?dR^wv[VS[KYZ]ԳX2NIJA&]=͂1v|t&/8c}~cϗ+9Tc۸j9L p9c!E۪䙿hソd=#RWX ^_ xM>Px݀Zv&.Q0hZ@^De+󁸓R]G,C.hITڀ7N8?\b+[n4/ILUc7Q$-X6M Pu> ĦO" wyFe36)^"}I>uq5"Q"%r9qe1JO)eLf<"f|Sqv:cUe#Zfu|]TqHXtljrO0~^z]IV_v"3L AK>+nSxBtftNASAsP@!P˨+'BѭԴfUw0n9]ʈ K:jӜWw3ȺyXbZO\K<)\wkH(z.wj`f^:#QpMmG_]0=Xz{_l _:W_s_R=X sKiwR$K8*)3(g$#@WPK &Ԝ~!vYFmۉGMrP w<ʢ-[gNjv*\Ç=ҀJGLLD-1/ +^2M+mG:LǠwhRgh^ʱAwxNv#&Tt6(\:aXW/ }7opGb$bb \~C[9[$gqH0ڷ5v|ЉxL+SDC^;սK+o#oO3qru62(V:/] cpe?ˊ: XN ]ʆ{ lSMG lgSh/qUT\4Fϫj^;pJ@l(Mܒ@'gǒuY)QU FY_oV`ѩ!U>c;'-;\OT õǩ)DT})ɞ+u@S1UFf; $>&mW8HRZR eijâ6IOsJ@Aw$ʰ`uX)shA:$Ɉ@l5?[Y'o+'ƪm3qk(l{i;KܢC|XW``"MG O[,Wf'ا} ;H!*EUdO#֠ßj VRnʔV\xo Sd Iv cq!gɁV.7ޒ;T [L[U!tQ.K;+}By hdAi[GjG δԺqըyu6t C"5!`|gئւX`T3K]zt _xfix>gC0fW?{<kQPqLcvsEI^8{RFCs_ԌQ)'NХI4G',ԶX{ .P[AJj`ETS' V©<<>W':F\(:&~h_Ee%Zr+p"݀ov⪐*)n~i_\2Ց,;iFvOJf-yqPYlJIKQMviM45~71|xR1bzyb] x")!V!)P讆G@XLȠ/A/ ~qKL;Sh]95-R~ Vrti!HRms(I78!-fMb{pd:6d`sj{VGyJ||!')6s)BYLJU{!QKAuÀIO.KC+ӞuW )d³NT/HG]?K+ aTĩՃ=՝>csƻs1gpieXw`ˇH 6X6 c !Κ]SC.3!ODBWQ(PAaUIԁ@`jBs ҎrxN<9,H%)8 S iFfSIxs|bҢ}<:~7<^'lC uUI|ߖ1Ԕu Iyx+.RԱOV.H32iZZq7ɳ `?kI=PJ!Ũtd2@0mamP G:t $_Ū`c!ʃ"-؇=ȉuZR KıVAbU` 9Y2 RNFu\QȧMm^8(ØnOW0^';T<~8sv ÂFt&ec`ֆ#~`]~:d-~Ŧ;s[h9zܜhpv5z >@zt*QMaϕ uPՂUaU yM<'C5Z2;/\eG+"~o |&N$<#:sHnXy'*nݢqj)$|Jw7!d x|L4~ЩRyp񛭔g1 r8E>0a֞w${Z=!$K *EOVSx'Tos^hM00Duu/9/,r?HJ[k9ڠE!?]D4$ Ēf|/ mXhTwaDpbX.ʃKGoʥϼiE~VdBC팒qaūk2)ǵ9 npn0 J>KӤvdViڣDt?FڑZk&9īRfFf&+&qɃ9ъ&yX7uB g!k2{V%pqH#Nob]%x?i'4c[}+CkN8n;m??;wa7ynuuU{gK"o!3=NXKEzM,pi[q? 2o yS30@hL"q׌~[).k|(fi2!3=c8&lv6<}Ut'JsjMTsb=F1tv&PY*kY$gU)B% `F[F^f9CJU.yz@QjӾc}QXb][ă0i?BfV)-Ҫ ~"CJ;_-S9}po\8]xP]Ŵ% d'sV4 +LB}᥾@ՠnhP=۞By7>U.p1I8Г2/Z)JlH?H󒜭`IF߂ؗ.xl P&߆1^ -{LQ[dZz=p̴qk;a(8vf+)2Uc^!qQ?gyUqSqƤØ ׀E O1<#,@yN| :y.N( Aq;WQ66HNWOUQ69sȘ9- :Rk[R]Bk#7tg5uZ;&!,nx[/)*N-`v XM6J,(KheE6t"}u2N)fWye7`8I'Fi2d^|Uxtpiq}yQyLtˠ$iH[ni o h IYf-Yx6voQxt"ZQaP4;^5*)vF[dlCR- U5˱b}P :©~rJ*mԕ 87^}M N::t:EA"/߬LQF[*PϺQ>b%+V'\@҆ƺ_r5 '_cb{,]kY4ǹx5 UQʎa QC^?g,J?s4r%"J,$H!3FUzu"W@02TbnJ < ţ :;f*{3ӱ1VݘTsa^ zbl\dߟD-$Q~!ǖm@D挐S#~+8wN!#၏6tO۶TVh=Nt<JlR'O eP-p YQ;;aP~83U%(ܘ|GPd46HCǭ*eE6ttS!{Ä[~inhrrJ9?A ӕcn.wISv85o+'K ? 4cT c eUqIl=Wp ,RU_T7|]y~5zu1Ϙ__Ỡ̄[ 9N9~?ADLD:{ү;Ns-bS]}Sq0/2i8̤ ^âXŻXMXZea_9H?v;ђ88d? J :%vׯmS&i?̣ <Ǐ&!z b[zONJN"q$MszW"#鲎 vfo3Z6Nٴ MsZJ }b 2PkFLY Ssq"UeVw#[oߢ7G \ͭ4E59>SUٽ*,x`N)*]xd0G/:_HāZ;n{;m115ryϓPFaҮ0Sݫ?Z=| GPLhj" iXeL#)F,Nɚzi$kSTz.׺!*3t5Zu@x2}?9a('-ϩf6-*z/d3~I0jkJc3^02'D3z 5wrHrX%͞g$3KM@5sq 0F--ѣn'T>tC-l(:q9wF ճjykN$qO%jP,f:s,W =U {B'/A"p6Kd0cWV뻌Jz>^[Zs2UW:2['C.FWg?W0#r$qN F֍dWDj (a%QF0#+"/}.2qaw=Alzh& C2|{_~E&Q |ct IU +bDZz UV9 sc??R yM{f|੷Oܨ*ZU L_ ;,GENwv*hCICg`\ׁY-Y:v ީ7A6IMX7'Nc40W* SLYҳy2 s^eOLmvjZ̗](\WbwjҠ{ral3/tk-z jBpeD0汿ֵD iovx1D<RNT[?),#{-\w-)FR' m4J^%Ӈ|ޮg]mDJi5={& H)tQ!˘__h On$,֞ P\gH=vpo&hh&c!&CNoQ!ƒ'0h{9s귟0WtGr91a@ 5_u9hje-4х!q2^]yց(R>֯6O'󑮇Ou~=e|تcrFTH/{+?94x닻A#O,s?*XP܅ qKMQv C{ia#.n$<4o$܈ A暈|k+HҳVچ-Jר8w.x;0]OKzj﵊)'˽&1 *,pלE9cY"겼9托suxد/E&P̎K~4M{Jfx ̸P-aВt%,zi)"?f>C8ntÑφj-2kZfo)D Xq!f4nbLɚq piy%._cW,8|;V&pݦjnd, .wRR@T(JPgJVzgJ"iuODȥlWI$lcCt1;D RxD.XVz.9ׇI죗[ kIl,d'У-뵻 w Ru *;`!y,)nK-'? ,;vFѠ%L wWwA w%%5N8R[%xSª"[i(VX`}Qf" oTݙZuGGud!v]btd\u Y@P:=BJ{JW]`8;~:i?PǬUaR۫7#K3,٢*kEUff~tL,db^%֘Mk8%(c9}pp6#mܜn>|knLkmeN`~X^q1-%;N/(Q'0yt6~g"[C4:7ˬSlRh-6зчl[  =n4G-b* b3 {SVjc"_#EEr;/"~ "9\T,̽$%U"Q<K^MoW'LvȉXW",_mM`'"_Xl5&rm-/FO(e+S>.M#o7]سGmTLm|Y)M =e ђ⪠4{ 먙Vytf<ً%8oJ14cy4xkϗ "c+\gX.~{Q=R?RK̶L 7OįxQv*p)NS'E<9.)Zy#0Q2>='iX;;VG'RU4+5>T3ޒT yegDnCeIvܪ2ep#AsOJ#اe RDjw3O~ NeN3g[.z[G#a"oDE" si)}Ej]_x6$U Zj*Xj`*}ί.Ч߷[^GWY"O۪p Z*x{n/O/Vql J^xϩ8Bx 0qu怇 :l`O"h/]e,1<lco]sEt5W* yIÚ# x~m[0zN.V@w6Y:vU>4$&vܑ00ōr1A0-:tk !)>r ҂ܲԽA:&0=e`qb.٘ spLJs5o@e/nנ @N"؁ Ԑ1}OY1FȰ";!۟s~qLKgznIEE֨AluЎFP$0HA9O\1eI˜JT`̽"L| ~~JH!aľ UC.2j"~ Ԫ4jhJsb1z\~x>۩`>k (t1e;?2,9D'L7N_gݻk#Oތml_ﮫk ^>fp\2o_ 0#ct@W݃îZ}`b}]r2/jCp_pi9 Hzp USLZ)z ʳNk6Qrcs5WjJx5J ktThKEɸ`H=P>4LV{` s.,7ANk% dV.&Ul-R ?+4Hxr=gSv_%ir*9KuʜیeU@\x%|Ry/j]I~:c|CE`DL=ix&wɿ2&@p<tOѝEZIә{%K"|aC&T7CZ][tEA~ )bKťV=7d-lt,XLYHR^*:6+tIa|,.|=R䐼Xl56 o{n4J,HZx3TFfi fם,[M9m$ҫ! neDAމ@J*.Ğ~i9uMHzIզ۫=ì0Zˠd`1wݡqQG&6n%P`w]*C%4]좛SAqt`A(r1 CÓ/t39_m.9 $ޒ3r+a6s=%R9Ռ8[a XPvWYETfCeo|(he$xi:8[/,7]'S_"uw1] %V-~5ש2kјB{ a( ۜb#;fFYd;q<oA꿠|O%c*ș2@4.t+ UQ< A2ҧV33'Sq h҄$Gv lEtOu2(Rʜ>PeX$8 (Mw2f>'k 6YYI&1gPεF8%' I8{I {~"/"Kn1p2''){ZZsiBKg"8u/T1# =`w1±?͝x oE߅F  =ʏQ&eηS]H|2`_FC{ !p>zpsa$22~(Z;n]Gz&7͏:sBLt~mLe/H +|ql1,#M #ӾLpΤ(6wDnCCOf\΋| ~j6{\z&F& rM^|t27i{}9c%*C!*fyrHXyl6 ' 'GVmEAw}  c,ͪ_~\۪2Md_^/^fGlҏq!ѝ:o踰9|agH0 ]Gڨ|b$ǝ׳93ik ˭&>GOQ*A+諩} /ڗbFFdH.Xޥ e[0{hnO3btNl{75 K nyu%39؄؇._)OH{nN 3z(Y 0Ӛ:`p5 1N1X E7;4Kʝ^tZz]cy%^6_`U{ߢNkrQWi2BɣO,hT]%%j-:$ʨ~db[ 8e!٠hLI. =bhr.JsڐEi?MlG>b.F叵dIgH0]o  i+ 2BZ,z HY*Qs<; ;~H9x*&d*6'JEC\L.U(ϞplЉƜG,Ɗ*z6c)R 2$S/tr oӳHx[w374i6'mj*\pњr!RF4J`G6A"!J>{萃 gi0&ob{,u|6Ȏ;. w B#*>U|w\j*5>.m~53Iyl h.}΂&&PTӑq0T;[Ik\Uh"s'O.eowqEi{uJkvN[w#8w}Z>)K]kw7qƶȶ3J?iJ2> 8($DHšvm],rz=W)hT ҐY2-mg7{ds6 d|_\7eJ,KFw W3c//ȫvZPʼT=}S3C-"~Y7Q/J H*3 ɖO&C|ޅ(:Ep2eWHy ԪBP@4H˖1^@j}w/AȁՄ.t'g󹭋 CXѥ]o͠P : 6΅,;n7zh\}_X;ߺNS_:3e:?V\l(3}uq&JtP/Dg{PGvk;y֮8oU-}"O/}o>p EݾurAsV&>#3Sl59EIbͤX!trH`drSrJJ,5N1l(팻;zԽz›rs/`Ta'/ӡg0m5/Aw4n1Ep,%h(I WtJ/Bݠ@vyt~% =O҂S=:a*0ؤn1;U$S0[u*jTAi$M`õpc3MH=O`=?g۰^ ~vP1@mb38baaB WD.=nUWA @3|Ir3z_MMMեl"Qܝ{gバm*̾ɑ[@Mjdf~d&xãi@p`6nH ^`u _SEبй+1Km^&aD$#Hh֜<irtCT9%dX~ E{̚T$M̎ѥY8 aίzDc},ә k*zU}SpmrJ5gW^7i}_9x%ku:%9H./JKDR J?iiC33w1܀F%,Gɦ,?}7ɩa*("t)Ͽ,-e*MӰX,9\܂ʰM9qso bփ6qӗ l䴮MU=6@$⇙Zb,\#+1Ww#MbO.nKIQ^5. &u]S>R*\vZhu‹́Ӝs(mp,v5 U[o=wkً† W_Lu FgdcMWd .,bGPT)dLAI'L Qk}8"h.He]J -o8nE4/vܢrձP]2H'%>֊9@·&o/~S MD7ew沖um[$bsF%I+ra 4dtBw@Pjǘ;@%&HX*y+/mEcd_iLXp,À! A,G@fVI`*>2fijWJo}~9.gK*3'Í{ϥ.Uq9:*"'gֶss!mvb^}}#(8̹{ٞIK`Tl1*䘌;sTL ="̬7~dx6rW:׿C&c#<ЎSo 0m‰Xӝ̬0᱑ ? rZYj'.48!L8]<{D&(ɜ)/=$$JR U YN/R ky=x{AL݆ۘۜ~f en?!VI+Jw.l=|S9Y̓2h]¾wi]uU^['f1U@ MG4쯢ԳhU01 eՑ˙acRx(o(CPO Te>}A/Z;݆ɍZ=PJTۺ*rCo^2fˁ+3IΡJ5ܱt $'9H t cl3/iB}7x6*vyr(? &N^R:JEeo$>nSP 9f#MoE:G'ܯ}D 4͒{Nz}OS8lܽ(kYS~ZtOC:}M| >B'[R&ӻTItuUT@:Ⓛ\E, z}4aYƶK/ym9 "c&'H;^ xҸTINWmd",MG;mѕ3 %A--dִ/+F!c:JuΝT)ؚ+B9GAGnZ\[- „#oT!9H7Y'U"hwA^-Ew1d_G%R)b/8C?:"*Bf",eȕd.*nAM.Qc ˷[n-OS_\Je|W~W8TJ, QQ&pd"ؤ: K{ي'oùKJ^e S@ITY~MK9/bZCW {HSP!sPe7hݫ 6ϫ˗&i;|m˞ %jLx_V6e Q͈-&d%LTvt"9a_ClWc꾇)FK]ȉhAS O+Y.#7Oz i$7JAstL=*hDWVl@SGp4Ǝ1x".5ABI^A':Ҵ"qK ŕΗd$'eu6%Ey7*@;NIBY0vG*gF\^#ϝ |EukZɽhlQM1! Pil*~d[rT16ZK{!Z۷Ft9y5jv8Ns=M 2'U].\\VȔJ7qkPDc 30Y>/e;rh:H]prXc1Y}UU8-Rdx\c'c"$ϷX'Var Cq#2N&0dށ,vbB װJe-~ @d+"$40@ie\E7wFnX#>,(;|t'kqQ6`L}yEޫ뢶|P~Dўj|_%S();'wjr Jb%iljzk%Y9T [;dtSc|'.aɡyCAm͐oX@ lI/ x9".{L'!8hJFfY~Nx hx903 dYhv^װ$v3 *cPo٦y =0\BF.˷rG$1Zo@hX۫RʎIkMmsQG-K9oXu&NҼ*Zv gW1-bv\SaU ֏:"-jOY]42|h3mTM{Ch06躔E&S{%'wJG)9t[[{~=tW?4$gaHpm^U!:D \A :*DJ+=.ΒI%pmg# 9:vnD1&.<*=IUǗN/.pVF dQW^P~JgB]ͥg{o$,T>0Xe{ʊhf/rbη$ wU )ATu_[ .-L *Y\%Pᆆ.D' u^TU&ܦ=wbrA1.j,3h2zĊ4>d΢wLX剧 uݹdDFMmS6̧ie E#BĩoL}:?Λpū|B}ԅbؼ;`F6d]WNi01(x^kq*=N8|.k,y0Q: ^4hR@2ֻP$ByG"n y 61%`?OR v=,VuA :tm8D1eP ɮS`03|`2Ku2~6Z2 S@nY]v%X>$`_MӺU6YdBLĵ30vUA Tw"Nd:c|EriTyS3X(BK e]xQWF}qo"`}OTsm>6}hn٥ ]_L/m#K4L2^!qmj)V.3$1<2K=z/e* = EA4;D{0%^g (Q@]2Ov:V!W[K\k$6$FZ>5l0ߣs,v&2[AF[1?)]1TyH˰#A`| Euzc*aٮ :5Ob3^\PlC枌4/ˇAa9RX>'w- 5hLѩc *S 3@\ "}}~9B:0#B H÷z긔.^esK>'\+B .KD\1i֜Kv7N5 wsơL۾u܈]{?D|Gnߩ!xv#@vLCMe,m{4_@/Fz1!ntU4۫W-4d͋|b%旺%iPO'vD˷2@=h^lK"vx`kBԇܛW҄[o)7c%P°!t.y,4E T9hdFx=X҈Fl"ߌ2?fE!w!)' }e#=ʃY4dp]#3;˽B)bSw2D ~&#ÔlӁM1ԃ3'>ݕ{?/0_?KdžX"{5xz0oc{%A۞.x04C9M@%졈J$Ƙߓ翀Jkձ1{qnKc?ثT;uF1YrM=hos6cvU'x>Pt$$TT /0MDbs8/ Ϯ;,(HUxd{/d@ M0,RaO7b!mPGxMLvNRۜ\XWKڢkQuR/"gE{, ;}?!4&}2îݓQW ho :EhAsyڕo_1^/[~*߲&(Y\ X(ssԢ(gtS䓷6:|< tELz7{CRUsNh@Bbp?f"yoGl+s.9vuW!\oB}5Zm2d54nǠ{f!2CX-:{r,V~|̊av^؉4DB}8:[0'.H.bVGl&\yhf &W#M3pl/~J~)` n=1>e}NZAXLuޮfq_jyf8RCHxfS,doCe V2x/mDּ-PYPΤaAMPNڷ)T{Kɯ2ҤsoпQ K4F͢fdQ)3s/XZ׷l Ei'Y/8[q9b\,:@>u9-倌}]g‚_G:&>r'@V 5;Vdi7hspy֑'?>kKFA-Dy#||D SQ]03mH@mD41,"(>[&(er حC ^f0}2{UlV=l0K Uu}=Z&o,m(6?G+Ŝq0Z|w=ކeCZd(=d*9AyN=aoܭȿ;89M.ay3F:Z<`Ȃr3dqk:{OdwDX R&֠o8Ly,K"^YJ6bNoE{J[9brpqfP?J"c!oؽ6*PI"GPZ,K X<*Eq0aMGcSK`)1%tk/PHf 095#,@ 1Ne[v<`&q̈횤z3e#y]f[at~7埻vY L GwӅ3݂ʾۋ$=@ ~pwMTBr1-J|-hB^sj/R߰wnr,ַ弟'Xϲ€*~ɕA?=zV_xHkF`bsw (Q/"aT~,00mDQ2e/"%< {>\dZq?g~Ug&$Ωc!-@j~Q:Ht߆kLħ|8vOpݼm=tMW$<:GԤzH_ڂ,'ưwSS΁~.-L`I(m#tOg1rliRNmw{QJJKX߂KK=<+7&:({T @ ۚZ^DSOʈ`w؊)(j$ϫ[tki{k8 d 8gnΚ$Xc)Ft^ U:ZƩ` nt0anvuZէHK~͹^4Ol i:l`8!$+"%D2vfost/Ò`3Ʃ W~O0IYQ P,3O o!W9~Nr*&4éwj/iǺ㍠ 5xt ʤ=\7y_oxW;̞b ֱPMcDGUL]v ڗ񈑁ۛ>D\'kn|Ѧgn;Ipٰ$TKYyx?vֆ&4$ů, Yh.cڬ J땋&upVUߋlR ^\miKTƣs3oǨ@os&VgF@>$O&, l~ǓJcwq+Wt+,*0S  }j1"~O__Pű$J+s5o׫dUTGgY!g E]mbs9!` ֢ȯrjt,ta67@: d cEb; &fL/[ jg ,:ZȎ 5O6A'>|w}s0lmGDфwL'(b91ȹ=y?=J ,-q5IH,b\۾$riWLKYʣ̳p ^NH: XjZt{7^[S}wQcEa vO:vgk35B'ɓH dqYE܎o<~T(z[̦ZDq!xL{~f/2 Wt M~s)d+]ܔ$%Ta7?xf%ǜwm:q2aFjyp:N zl_sl@PE[WT~D=K< (Vò'b|p7{v .kdR>7W\;rXbleu*)`1}sb&B '&bXxGto1Iug3E}\@mPY!e;?5O3.nÊЦ_8HL%oFt0xV7ÛRԤ`($x\`bSRU[:W:AeHz8Q1ZC4UK@ɊޖlS+,#!l.wFbA,!wyaaWvv |%<|v𜺐?pH2 =!6-0ڙ+WQCC ιkUScf tz` )ޫiR0sWuLtH_OmAmԴ.uY-xR!cY9Ms܌h=/0#s$t}lJV7G!93uW:hb.WeR+p%=eŅ3c8wWؾZkedVˁ5Ou&$OQYw :ғf͠y?X KbnټAg3;i[ۛEfr8r=';PF+ 7"(3RۆݲF&Lw}Ln}ĩZq ͈,s/p"lSsAGeV߁$įl;rnDOr_^Z$*;7@oo/_ G$w~WUD5uSo-q)p;cV8'V^pE&ks EC4yd Ƹ]APf6$&9bup7l /VT#8 L)h.Ӹm,99N_>E%+bWwaqJR ƑC%>L8ͨ{A'S!);Рe6${a􏰃.n&@ApWo[66 7bo^"[o wr0jv[4^[ "kHA- /Y*0AҾv `"%we2Ώ `@Ղ%bMj& 9!I_f Rj '}[ 2{5 aHZv /ۖdrtZNJFV@, }[4^ې%"@K[!T* 8Fܜ6n6=D>j@uo;U-?x^kNzDaG7kEf~ 3nIR21zAb׾h9oo'F>B 5k..SZԳw>39ְw]=]}{a(i¥:d][h) udD|w~LT6Ͼ-:S]%R 1{&&7A j8P@SfJ>:Ɍ(tw9V01\>s:WB LWgQ o03+dl'1'-+!5e ]aң~@ֳ1rG-\mG8]~q1XrdCol;ɠ\Z"c{[RE'.*H( VW:W̏3ZyRW 2w>q*Tq5< NG@DPg:Ba <Nx\z#;VN@ΊeT -7cOm &,$sI)* 5X,l| ]j/-pMT9 %cdM+w{[Ͼ@8ٯwUUW֬,,%G?7O Rnj04A fO⡠vrdB>R(*&O\cat9+ x6d{SHpcwk;*Ӝē;aɩmI$%g̯S/ZY*j#˳i̜%'%c(uZ,9qRwB% 982S u;*ojM 2H^23;t':,,9qxnw ; INw5*U7 eojPoߜ譩W-+sQ>}GHM,~9v~vP\UKɨ5[$h>Jd \]_yV]"ͿRY%)lwqiKDPO 2rD(JR*E$!Pv<E73Wp:.;p ^ *Ij6ĺ1!bR(υSjJ_N1af͝x cY؈uXƩ ]st5 T[wWfjי,+KD IdYr ܹԬ{/'Ϣ8,}V|?J܍Z[^5k[DSx euM\%EtXy( Xo5bc 2т=gOx!TYUkJ_)љ3!Cf_4@P\_['-!ӎxqƤ.:qNMd!P c>-QD?>52Siu]*BJL1ǘhѯB8/bE_rCC.6rd T؇ Ö)bT}s4A6urbw@~K|tYd@d|\Y0QQs}YX)c R&& v.=QcԸ군disLaDZ]ƽ 'ʴhn6%RS/Gz =KW(,"7or) '_.yW; B᪖b]:^8m'kA)9)'L9Myz^mƾLY\]8jҜK_`\6 (x:1~hMEf2 vyWnQl2fz߾/A[ TOTuU'X>p4o!a%AGܽs[bԀUHCŪxm*^Jnp)~o,O|piȐea!hL @{^Ec* HlK{!>6g8cUĎE"6_uZ09d5WF?F+ _/L/}ڑ$ N#}D(ZO 5 ~cWc_(R+ʑ:Ҙgi"vvCN 'xX Bf1qJdZ,"~ vA^j@j# m:ǜ]dZk°%C-,<˕Dku. Hqt&קm%T,•GKxHIlV`ET#]ǗIǯG[IGs "(]͙)‚ú4nyŵ|藾Mp)٘3^Sc_Ht D7f?TpcɊTŶamDB,(0a7owWj\ʣ?%c:R45"Vqi-7 cIҹzG@ hAX;#}SL r3ٌ泳3桿x||j^*BI IA4W[%.=鮮rVV)ErO$RM#8SA|L( dHC Ff-ձXgi.1't]RP ˄|{}ox"Dʓ`,<}a}bw{PJ۠xy)|EODŋbqL+--En/*rBT["$0I6>/|OًWقD0RqA㞨DT&^ף$eI/v4&(^>[DDI(O*I"P}-~ 0qG [<),2qW㢲 RuQx2jSШ|4)ֱT/ )vlf`Z%grImя+1Iwd\󜟂%EL הbD6YEZ`@>X\wMr.)˺:Z _6PZY*]2?RЯ-7>A;_Ζ98s؊5Vs@8%uy0L_P0KOMẃ? X>oÀ Qacu8W$b3.a%wTXOK%gGw&}7p%>s"-k\.MDtmlg5/jr@o#Mc{w*vm/*efKQ@+r&'gfx +|OɏMT9(mq1q8Ɋ&}gkpSh%T+ !=r^ȟ:g17긪Ay3^H/">`M +Cلū\bpjg'm"pIyV}7 $XX }[ݩ/!( -/*ͩn pF9-6HYe?u)񰍸p~A=/VOUW #3Zu}0grl`CޜAQMaI ծ]oؗՂS։ J[E#xP&iPб-F2Jm #ih1pI8UvU#+Y4O/ZQ{ ^btv/aMU `FBh(*9<ܕïa؅!^jduUEn&X_|6oTPomFcKc̶bWII'iC5P-;d"dY965n/\D?Wz;Dr68:F8m؁f?1!/x϶eL@:aknjwn YZ}b/\"EVQ*֮/jY阰`(,g*w}S;]Q2^}< bۑYZJpbXW+񫠮͔ܲo3_#\CdFa}t= ey2|2wdImYx {II?{=A2: yx_J"kmQi!W%;+e5BC=|&s-}d}7AɈQ튏O\gtH(#Yu[VuyC!kˈ}Q׌xͦ,)ɠH9^yM'̓ڞׂHjT3*]JG hq3=^΁}d4 Si㫿0c1<0(~ɧH+Ƅv% ^ea|Y2GMggxh>7qwsuI7e|gJ5|-Wjx5|Y u1x|>R׍aNx&{Vd5yx8#d.aC&9$Z`]^ lCB:ʪGMwE'rމR;&KRk$qq_>wxtt!/*[]";9XxTX)2v '\>=uDF@P?$2")w+[3< (Y0'2'%X^$ib[>.4=v[>~~KF}^β'>SyH (򗲍5ÊṴyG2P3*F׸0ޡ%ҧB@Sq(3+;d Rn]kR2Pæ?8$tMڏ P1 _W8B DY? I*hPCS?&s]|)B; To02rЉ8 t'[;&$E@l>#FNb\y@;t/=v=AGoolQ!\_(*Ԟ\fX4Aei8_5U@ԕC%~k\":6BǏAd~|-6Y䕗7,>ilYOCxX*Lg*)Nx*ˮvՉ\̦by>ffXSpTYlI.x4]`ˣ *MW%$8C uCv k$)se1v/ߍ`ƜdpɈ\/n^4zR2 b$rnUS;L 'p:VM2ri]0g.YH~~cs%hwyVJ /_u?E䯳|o@ N Dk-bN@¼3FIZB<+v]؎yܑ/W-Btϖ~;%ۯLCxr ڗߦ.v|agW-H”$T2>w :2 yP CZUS"O`NgX===Υ35UOzY,37JD|`],pvpO1~:  1o;yD6f̭/hǯD5{5)WWog#OBbxecL$wc,'}0NYiq7+"VtZVD!9~/jaUa 0-D:%dZ'yO]#2 o$+~u]Vꄜ  SGWMn_Wv>FJy092ّ72u֤S}]eX*FN-+I˧d1$P޼- NMŧWd.Ķlꐝx'R}n5C. Xi`kcݿ.+{Dge'=lӬX=|@\ HF* bA>w1Y~:'"b  tՄ^T.xj=]lbp.҄ܳ #4\ -ϟr ?^ >tɟQܸT.m`[n+ ;3dh.s PO?8گ"TSH.HU9bZ.ig-h>OU/v-7r^;>@>Hi}AV͹b!G|Io`59x`QHbomݾ'@`&U$[r|Egڵ#$A*Ն ꄅS )7>-*?7-5n ̓e\f=vv" xƑ *aE0gVJB@<12 &;Gs4w\<„Q^LH?:T_)ߖȓDVl k`n47xAXit~Hj%#ωE~[YpYY0 >T.GԒ3]) ^{FZ `/>R!$ _;mf0nrh bmFb7=V%5zj. Aő N8 j{RpZ9\W(uP&|yDɗ0R-K2kFދ*UԛYKF/"PvW%%&/ @X gKqa>w|8*[^*02/BNCK/i 'ZW qmHQ&w!5deJ~ECK .2fE@n `׆$bCyܼ1\ c eؗkGbPJid<ëm;.3#Djd0=?[,]*nՂQHR[um?{يI!IJ +0WQm»P*l&-ڨ[NObw6a 23m"cSLkh_qiL@&wR//4䲋oBŬ {Zk72d*9~=sIa#=RPdB)=ο'#L[ dP&K{:xd״A-3咃-X,ih~:Ҡ| lq%rf/>ٷ Lu~(B=79hNPThqJs&T CΫb i"2 C zF^ omEޭ&U ` ŀd1DKMdhsڦ[F.f(ڜ9,ǀłnj=p!3/P9w:F|u:!5*Vqwhቩ'']57ֆ{lm:Asu[qws;A^Q| #6aMۊZG?Dl_^=(-/)$0M02'+[j ~u˺m 1_FiߢI557|ArA+$}A9,_J9 Y _ѱVxy`%u'nv1s9>W/Z봪}Vg_TLcb[´EDςir6MSR)mg3QbYP sαd5?אX @WQTʡh6"ԚSo~#,mnj(E%+:8xj*r]WgE|ȋo\(hzV`E!T %1 *LK+ŀq.x^;leG֩Jbޱe]EH;7_.mNWK B~K+T{J Z] 9Tو 2d$i`0C\Ҷr1?>6&#pjl@ n͌cBvWtݐG~q*?;h oג(Ss.ġQU+džcF mr2a7,/6n$=F$u`#'"ARQSHCۖ~WaӿKj컎B"q,H=꺶,~,%r/'G_v!P,rb$b[vqHk)F8Ncy@wgb&#PqRF㫢eGh͡Zؔca. Ii2" tPaX( !Zq?љ Bw0;Dh,6L r_WyΖ-(ޡ nj__:'`m3UZhv\K(.NVY J&fXa רO2sEmWDyp۟ bPi6-80OC{NkQ6]N6%FD/SfKKGaB$۹ms-kMd a*9"!?gM:ѹqt<8% WfExoW=Z21tf}-w1G87E,}- 7(ϣ:䉚qx"&QŃӁO&̞S.&wf6Q>rt8:Ɇ`.y S7Q`G[]%5R {;=ùI6@m%&辟@Zk (D>?`ggTSpBL ΞD*C;}ӵ|<A>˕=pG9d3iV"+4y_Q8ewƣv>ulj6d[*%N9UV9Er!+LiCKGk-|vebН -]~>M΋]R(jmN'J&-7fAf&K ;\$G]r,Ȯj/ćMÚ?DrTحI1Yi  Ák շufնi!úlz'dL<V10Y/,sZydnpB!JĦHTg1o?#ffHC + =x_ҏ˵b#]9,بuhؒ5VyYm/mM "\uzTE$˔6*0 ˾ 唔2>4g)8vnCKӖ'ABG2o0fZNJ0y\GaƜ/}WOIB3Q{(.H6°(!EV.i$٠"f$vZMhjXmH~>yȢ$[M0z P[x9^VOpp6{wnMBq.9ۉm᭐$,IVGKʕq=xc\lϛ;8H6 ȩ㬮V csonKq\Y "ƭŒ35_`RD:8zERa0B+k PtY ;I*iA.._J)Zf;1"|Ed_uj5 Ƭ$U,{x:̿1\iNIF MxXMX3CiroAʋs84¿&t" m+uuq'!0P RqA` 僮c`|T¥3sxY.\p]VV:^#aLT҄KNq,QjLi! Luv74ʱբ\>ߌT9"b"$^G<JV<AпPL3 +f>\~`E{\YӓyYQqwe3I D bkMrMf"3i+40+2ύ@A%ft5V.ăs}BTFUR=Syl/ŤycupQЧV*FT<4TqiW8:aȩ&2l=:q :uwqv1B*7f&h/m+pUZm)Mr`7Xi +Z@Y*G5:s2 nRJQXg,XIq fhacơHl!w=?E.`.GmدG> AG6͕X:B{IHk\wu0NFM b9U68yUZ@e"Zͣ% KZ5X0hx3礸]-Llm70qjaASj zE9R)D1&4R;I{4)֭뎹VP~ɢ^ .sQF~ Ę)$UgϷ7PPN; 3蛎el`ﭿh9u ͰE7fPQ2ơ@[̄stjϥbܘ]^eOQjP\~oE1Dlu#NpdL] MTZ#䌱@o.hD{4f-K.FpM>iݍq)广ocѩBFBb*е hyZ>4ZUg {-@\P=e}QҼtWifa$EuB{|n9 }h\mڸ=/JY\\SN<;Nyݽ~!e&A3~Na_פݜq:^9ܓ2΀MUO`pC/ϒ@eYoX׈=PDDR:q&A+Ғ߰%hC# Nݞ&G5C&quPOw-`1z`3qWj[x r#`:σ5(F̐:U jfe$c&VV_jq{`; #/FbytӼ^RÓ+͜ouo?vNr{$$ RlK+~8+wM ]8_}c5|p#^>F-#:VQ Waٌ_.~uTŷ6*0 >w'ss^}d;{00(UBUpQ@~%I8L&f e!{''a!{9p{T/Oҧ%1[i$F7+\PjXVHOƛl-+ xWş',MEDwMla:@*y̝y^c,H"{s~g4XA]5)R")̶HkBv\4Z:ȓa!}Q0YI= cmz-cJRtK[reofZ;dKn!XjTcp>=bL9ʐ wc C9IaFNٟ ~$Շ3=6iSS,h= )M`*{φڥ]kVҝqߕX(?u"*\ѷqx¢׾Y3 ;{:zŞ~< 638joȺI[Eܓ.z4WGMnz˹,")1;v=.Zʱ^ *UM\+8 $9+y0\>:VJNg_ pY84>۫}TVҾG]Lf$;.•eiU˪, N{j Znpgv&"ᕆ  eWR jxJ ?qz{㕋!btLO(KS6E-ʜg k/YJϲ6ō4(l¥BL`OKvd^~,pJg{LF })#\z&2٭q86,1i`w`XRo`ƴPSx( 4pCАUoQ0+M= ZlK?|[¥g\P>rKN@:IkqOT(9W=N'x):qǟmwʡI{f((m]hkAڽ7TՓD=1uq' xaBz+tZ[ls8"[p'jRО}\M|^dAn^Pҡ[/.)i L?+G_LNZP"*&1J[FpE$S̈QnL~0 Q^ߪL)˿]Z!C7仇~92+ɠ߅iccDڡl$LiKl%$+-GQMY}#`+d,/pT(gL`Ε"eEa[$621sk>pjI3n5Qrl3?öcPyl;!=2fnY;ٍTv0|ʪs`B)-COm'LyɷV7v$юvsKUx\" !W_.I-d$"mqXk*z"q(Qk 6n7׆*`+FwD}8tvy7k߉ۧj%F-*Q5h"knp, kn# g#Ґf:`\.VErPyHAɾM\A?lGQb=eJF~+A8y86RXĎ? P-4TPI$Wq< 2KP+9mo=VMd1=ramaoOjh&Ֆ6?3;20bpPEkbxHAp`bй¥|AʷSjF _tіqSEUW_6iE"|ݐr78*5gMzWFq=Yii0IͰrE]ǥia1*>r'CuZAU 3TEFف`ɣѦIj8ۖ>b90k k^YVzNW󲋋埥,7gM{)տ:)xL?#S|=/xP=y)um"1oGt}I{KEHƸVr+@ ٿ'2Bj3u7Yq|?uJIhq w#q(a(h<}5c] -kYv/_&'yRA䗙@f^_>7i;º٥p`~M@O`Ь]@Z>+`ox϶kAߟ$g 7 r*cb{P:eSlApwQ*dYz#2dyZ*BT3]J&RWUe>qАjޟ6(?DyN=.1W 4S'O(t:RxBZ!̳jq<>'oT?80zxRoBͧ8x#Lf] ~.pL ,˨9O%X?y,:_x' .#hCX%|:L^80pQ{"Fb2|8Q9ɔNF+wtۋ. ɋfJvمf">Pd3~?qFÕ*G& lS"ʏNH!PncKjQ$ gb8 yG#wh)k(xBAL rqM`MZ2׃@8ތgDYx$)qXB}(,+`#iDݐ:j٭䇐=cG{Nj嶏o8x^ڡƃ;:w=kB -r-nS^[aHRrĹ+V(?t.֘,83tɣݩ nQn>97\:L)xכ;MWOLNuwq 05%tj=S l{ ёʇ6&̡^Z-E%`^#-)S$Ы;4q|F0@6jɹfX a(ԗE+zb& ϖ(q~Ӌ`VFK7y?$6~4Ħ*~Qz>v!ЩgI8zpۙ|h!gV\4Iq6ٜ>2'78ZD+ԛX3,W zlm<lҜ}[`mqZt)K'? JY2Je Ќ]ƪ-D?CY*uSRI@H*Jֶu7֪g>[Z:R"v,;FUIDs;~VPѮzHSڭ66$)F{9;<9Œ-oFVq:3T.Y#󼭛g3VgY(chv6rl,L܍;[> (oA>KךA1w_8qL [`ω`?-O%wTk֨>d+^X'0: PohTFXPĬsv|OKQ] ?%+.VY5sj8 eWmrPDeԂZf`Ѹu} ϊTpJodBk^rYL%7 ԕ6l 1/3CꙺoH#u/\Fܔg*^-/ePsxJ.y_s'iV_KB;3ys园,iE(8;L M eFΌGAH1rH7L ;jyMنEϖJPeugf;zΉbcl9q6e\+j}mw' ~h;PûB/MĒ%2H䇋w9ۥwDᔻmGY̑ߺ ,K05̩1(g vYdޘ21; bLӿ)b4g)hHf*q ImO2Gm5DK{D l\ OB$L RCpUʣ@D+Pa㢊H'v&${iMe"I{<Oit|6jDůs>ۚBuK75*zr&o Ռ2t[-;pk0Е%ΏDtD8ssf}20/(;'QS'k'd ӀBlDCF! r^`A8 &xC lviɯ9uN^_[u* !砑CCXd2)1Ynȓړm ]~a>`#+qxH KI,hM#,FդULWX_ʭ,ѹqw}t{Ce v57n[[];|xK:+~ WO\ lg(Rc87*aGRvR+ nQ:vh!h)s֠99 Y%Ns *;s lgn.v; h;tﳔnJ``#,ƟPt70$تѝ+VE7xjmB2Q#f؏|V.q \m &h;&U$ uz$.8Rf`ރS!tX̀؝*K6FޥQ4SݯkĢWN#U}rxbã$? d `[W$ 9Y2 ^p'/@&r4`q|PkM!}UMaYCŗȜeWSsH n .fn=6H<mL*[]}2ˊt %)suedm`2جknI6T|xܒRjssIڭQ;u睡GGE8x 9 DpVL1;ClV}[Vj{-;@y1O䍰)^l 0M9…U-aw(ԛ.E_@o[$?'$˗y>  o"R .dPտpXg(g=kF]{DuxDBuFq? +HPJ_ϋU#kQ״ |{sm ͳoau]Ba`Lb}7ăaU Ib0C:RZ%#Komݜ g*bb{H#% Q -: C r|tdMsT;P^so:S9(=O;Et ИUek@LsZ#n%0oϴP}$m$YrXix -d)Zz 3"+ϺqR%4#Nvg@Vd u6g3X)E% ]"/ZVmvWޓG=<$ږFBn&%;8pK#[K-g;Fo#qS+/hE}OLEWp3^-0|ȵ[x<"%&ÙZqequOO@PdxC#R ĕpD]nR^&#!Ed &ݴ}vE߾h?@f)~[9Q`Չeen6KIvLKrreN.y\zBetL 4QA V X,7'{>ߙm;/>LtvĉZo oA UnK @eaߙSȲsej5lV PnyA%ߜT}l6z?/[\F=S] YU*:9DWX;f{9Z@!nBaP3FzkmܰOHם,t$d^AtvC^(-N_ ߛ;y}4+Db:0OTrgn3;񉛟dSZGvh<2#]Tվvf%k.YM(Mh8ҿphC܃TED㾏ph/߄0soى q躦&w/\ 1FInjWYZ p~1"G-"ɔ4 l}I/H4dbvرsV jw1´ }E6O*W+4`24T>~Ǵ~sK[ }VUN8nz P4`xsRT3|*k8U+ (X10aO 5"O!7>16'`in:*YE$HKBU7*4' e x!Yp,akpD_(C̺B45*'S~+AҮH(+DQу5?2̥{wIq!xPMF;jj'0 y&֐S<磼"YHN^>TL+צ[}JPpQ5t')rSsU&O_xsr^H]+ڡSH:زKP.9V%Y- :^Μ.pQ,!V6!,jgRݮ p:j<Lr_ږ~GMwlI?mBrĝ'Lv:QB#2I*xZ-i w&.kfFѽIoGnN`L5Ń;d\y?ؗ#ylrEc,; _/2cE\? "νRSCL~Yt0:$~NO"vK;8Щ̤FG#akPޱwn"DrET69eJh 1mĨġQI=U41 uki{N?>U 69ҡ0zѡ0r̃;f5d~IlmT}?$uYpU`VJ\#B݋{Җ*%K/:7j{PAGs[29S1&5gI55ռj]fnybTA2Ze`. እex lO\s0w$pkBp!} }23#`2Om1˜(5hY+cb8=N Yxry!b"u;rfWJռ$.mq Kϐ1,J#.S\;A#xN xQOl Ԍ&H'fğ͔LDʗM9f"$9!*?*.JR(ڢ-j"\ ѝ! :֌ ?  a^m0r栗Vׄs测s*![O6HI UPBS$$d^k˜Gaw]8~i ;IDw ̓ `:+#5Ba4ݧ+ybUBwGdU Gb3>id8~%羆sȒG/Bygp9q$ͅ"qRwVpX6I8L٭g8^t1jeu/W mc 3P婽T.u߆?{Sm ZƚjU>&M4/z"U)QJ\-\cL?|ET1,-FQXMh=A᱘L#oED-1TT8Ϫ9LΣ vz=4[L'QaGfӉq¼ @\qHKs5,'9Hvc$~1)% ҮȔHHx2q?Z{_x@ ,]j2 Ho! Ksh7qY)|w]+пyBV/8Njh߻|ҘAVו{15+pMz],lVfSIZgY}mӴ'"pH7dHVBOdcпMCm l6?.Z5Xw"~_\e!uIƲ< PO +MIs~ZOy&M4Q©nqE=PDMhX 9Xo"]ozy- 5:M1 yZ)`ua剉RL.\>f:&nZvN5a8Ouky8O׶¥bXY)px*ha.ǴQ3bOw f907 =zuq3;! "iXϕ{Ԇ_ݭ^#STw3řo>/ OiM$t\QS!pXP}r&$B%Kjz=ύ४zۼI$ZB$d&v\9LZV6׫'B'JQeL^%eVq/TE԰m8oC7(>Ӕ{:a@@,u1o#r W7)J{Pak7`<_g8mPcϔhT֜5#TuR- IL <#ouPW/a٠@@Ƙ6VZn:-X]y#rEC/(_dm?|0~v . 1';J&~[pZ5?Mah(7+TsfGLƠ:GrXЂ@$ݛHf-aQ=,̸\ݲߕ4^>m D-潝 Y0S|[!$ox^}Aznj:֟繸÷rJPb뒘U-xNVPmߤy&N9G_5TwDP6sӱZu2G^.vKxG7SA=ޯW dH-&X+;IM Iw` ,pW̑suh6$T=B:)HmVmϔVB0F OcZru+ɛ]놄Flr2uZc'*3ѻb%A7Z'dE, ixs5R(ӣ9K|6X^ٿnv/VFLjdF.,JL}^.D.Zu!Zé]>|v-WHڠh=1,zot$R0! $|oV8$0A{=ờ_ 6i2Gk=~ς\y#fo$dNؚGwl~^# 'iz]I? KSyv~bWzr%V%,3swKYM'+-/f`|t/5}Cnڭ}VFb*goCvJ{HVnhkw>@,u$5}Z } oDķyRGX%A[ڂK}^ǔ}m䋏y1u:abCZ^SsAl-oJ˷(gPƗ_!6EMFmBϜ+jxO)n}āHwr]17+_6_)•n*6{<].ߊ4Ơ_ڊS7V*xʣbQ?T'ee}3Şmyԍ $#gfڊ}#k2+5h?L1Gw߇cF=)h#]tLIG[ԭʭݚN7=-VqVo+n"SE+dR|$ CIAlj Υg~ B/YaSh jA?J1,Å F.(mL%:4)8N!#nj䔞}|c\U>ph2JkQ. PolNjъ8PC Ж2[4Gֶ@r^g_:~9Og},%vqS/9>S? w^ Y} 3GŮcNChL9*{SJ;Mk{~%p H#,g1S<ʵJ.a*1[Ƒ&[;Z}}qHx T4B?Ͻ!u E_;U@u4}23HMw@2{6R2,kxzhҗQvswC슈Pٲ\jm}?QoӇv=mm(t)F&N?2DtWyxgUqIF*S3$$X]F2 ,g$A )7'*uGĀUcJ6}: cHi3t=0q;R"Øcڭ%|oo*DMKn4:[ݘjèJXL3oge_]`ݡMK{Ωo~X⮀30bL 62&,eل9-I,y۝0νLDfyPQUx!iȚ2m(g4vnK 0I%[ZB\!Ijϰ{oyJ 2jb?r72lKA46/˹נ[Oz,jQzp>H,az{(3VJ wgr@pq"1BtЬ "d "-OD/p4˪yYbKkn~>^ɼS'3}xL_P"uB^u,Wzl:rN_χm!p-&jEÙԿ3y`Ölj]f.Dq[-ܚ@B=6+#uS_~e; @Q b OH*2h ME:yΚ$%tB FmwJ|bpUU>:,ACvufИ\(@ܺOjs?6ɹ /r @:F!ٖ<M8eXشwF̓*h+i "6\xM-^mSDz\)o"! a+=E3s#,xG3i#+6=U0jL_}4%T#gRpwrS^82rGeu"ض>Y߬zh\/9c1/{0(%ZBq.:B5_ii7PʠIz+!KY+rߵ<|] EyhI|xaQ.N6>! eV4@k*՘{Z֥6֍ [޻?| g-a a:i,lr@QMG~3He)zߜbWlW`NBC;Z)G"r,Y\%K'tʼ?.{Ů#Lps)ZNd %%eevI]3{Ҽs1"e&r\Aнkj5g+(% abSWUlb!"(r,=c2wƎ}O*n)t: G95o} BFu0H+MS\qa߻J:Bm| 6LjJ }_ `#,عqG`9YT$nw-EPuK? L؉YuRž%|#TU!ַVcMǽdkB=X@`O؛viHl}Q *@8иo,,ftΊKσX.";@E6ֶDw_JE{6KP-=.yϚ-(!`@vgp#Pso4A`ݥ',I7bf[DsAyxm!×kZNzAv9eC7R|.3ed~5,xfR•f䁀'~᧽0z6On4s\,3V)jԊE*|$l?#Y+ȎA N\lKը^=Hc\Qi4G74zsȺde=xY(^2{Y^,ץ5ڋ9LN<^tdybK,BN͚ɃhfȊ ]9;MS ܎A$E qʼn #(Q^!~ O2DS]+z[E]OdeF7u>Esq-mm||J%HNjcf:yk9CTo2*C' s$R7~kk+F=e%tbW{l7+>[Ќ7;."JSZ+G j >^uQ29JQ{CM@c)1jMSerq5pj .$/ f`qtEZ:\ zR^FĩN {AmW#5%w E˂A@!uJ֢sW ; f""<5-G[@DΟq֖,ԋ"+%4٫֫_Ԇ q;jW)XZOX僁4~|kyzwEsոoFܘulXgv*&@xLvJ݋??cz ,Kk-M5͑yJΑw!5D{ T#ט@1,큜.C(_߭mCc]f c1e7!$2w\)#t u⏹DvKf;@s-h@6J{bKM|1F B<:ӲbOfpq 'U##V.8qᐜTc(V~_`|fZ(jI/ mQ!-`zkoyJO,"O!C nsʮMeTvYD_՚g7R6FeB50z=lU?3 oKi_9H6T`] S'Uj(R:[| ouY^ (8vDιi]5ܻ%m5(LˣNy1*We~oS"|'?gIe[ܤ)ݾ C z+Q}7h_ҒD߄T%M;AO|NXt=$JT(/6OB(g./0WQ"wۦZ `W^Qbs޻Ku∖РI9哩A`~oPy&yk{X~ YR˘#ӟ8ϢN6iPT〦SIīu{^,H /i9%SŅpa{lZÚmOzOHA*Bp/ar5/M@=T_ȧFFG;Rb&W$lW1v_ɤpE$ulMJz j(7oCס,==pؖd@lEg]= `&t%  Iw{3 at+&*6.ZȟCO;3Nw$u&熶)OIl1'7UkyoH,$X'aX?X!W7qЉRE=,T~C"") >7l$4LRtuP\Tg;SjPu֟È>. h:u IBʑTT3IA#R)Vٍ:*MR!P ;G~H [ & O f=| [|:s'alpo-QD<:|7v|yKB#x`»= eLk/nJӲZd S0wVKq&[yKt?eZ8uLؼ;.@BJ`- YNeY{"AT7ϰ5 Y̮yYsmmFZq?Xq̤pQA-0ߜ42<4TKK2V|T:}smT 1Y\/ 4Y_6vÑ;6V;- hGkwb o瀫&n6sl~S4;4q҅m PhrñXLeEd`;$AR:" Vf%Xw)?iU[5'vc+aGLoձ̢1N&S)S5M{ &u)^#RxMɟ3i4ޜc*b0cΜ!7uF%0 ^>k^9z&]$k-wG?k'W=S\N*lC ^:5I2 Wq~2M ӧS4?h"{VMfB ʡv:uLo勼u1o۴u,[\q1q܊ 8yu7cm69ʪ#cYLUNVԫM\.{ {c("#ə?7mc ^(4r#v7I!|Ճv$V2H T%BU&;M1/"Jq/sKޥ?4 &&  Ny, t=6h)γDJߐJwcܤq(&oxjˊ-S$.YBˍ(KSx^yC9ɡ7-N7rU9~s޹i2ƒ #CD;4 6P,zu 5utH*3ϷAn)G..&C(jsv,I Ps)lw[Ĝqi }U%x{sIM`!15? :f>&V9M_PI8Itҏl8v: w=P~Ҍ'V" F( [9b,o-]z#a^Qzj\!-_fȜ:#9TegVu}*P9%䤬smUHP, uQ8MQ wk/z}f:P2R_2Nn(2c'HTUG- 2*Wv9)dˮca\IĩRx]J婮7ebya_w`Օ eBifԩP[g<,vs/+ɾh -f r9"+aFZw`)ncxӤr[Z(P'ZI߯~-b-fvH(xWK-ލ l&H>0h]HӾ@a*rp_1YU<C VO%\I(j/5:TXsáb{PМ,j^! =* l=]b=_Ŋi˳s!Zqe"ćk_8qMNJ8 *nDFvw$ِ8`LՒP!) gQr-:*JIYV+0Jy[웱 ~!4t=1lP\ d% _ޑ:W F!&9"t*Bώ*:/V/Hc7:Zjw|t+z ^ZWT3mZm0&MȆaj R3(İ F\+р$))wt!*}, VB_wF*xa>>}1+ɗsBNc{\^6(@C3MG> 2k-~D?[УaZ TϒDwǠ׼;̦cwKR2M}Kt_ 㲒<>a=qF>~7vs5!x<3I*_v閰F~) WEV@9]Yk@&`N<cԴؐI1L [@i s i,Q/ P{}^k. '`gNp19Ku/tV#)'˅G^`1}e󸫞 mx{,W7&azZi^5PTIn GjceVԣ5H9IÊ`+`2#pdm{A׿R<mr@kA xD'm:yr+rHƷh8d -višK?nq5|<w[:ΩoiT4'y bsT\W̦((L݂JA7SoDp27QjZamp-D8Yf j g&S2 0,ڹLKv!+#Kne0虅5vX9X? *|;7qC YoAN0:7pg|e^g Q*XT KF}&3`}X-ǘCsi0>*&^V3lz|)^˥YN..fRxT^Oh$,R$ʬJaY<%PϤ RߧNf6WƑף,bWE|Ǔes`p$I?LoOs/ bͮȎBgC?́XC #\S(}5gDYaoG+Uo¨жa0܆P˒+[?ȓn58o5; 7@1eݮ tݫ$.͓rS a^nR&UOMzjI`r &ҁuU;@K|lܯB{ /Em/%4ezv`8nQO݆S 0G2D~:XkZW{; 8U'Yq:HO-RG.r ս^>) BXw3`"_%NQOtUs/o:nEV~=et^e[t8V(DPV(b~ siuЄ{nR1*}6B'eOMņX)(-Ln-e|1?PQY4zyxrJԱ9D8]^=`&.xfE1JC \qæc*Y^-]E0f/>e%5K1rMN)UU{_3GGǦK@ c:!Zvֳ_ox/F0 $.lď }X*oPD>*XA.%u<#:m`׬[GJ̸|%Dm\%~_EQWBBlP E"N؄L?ZS"p`>C7f*Eɰ%J_2SB(q5Uc@F|t-J"]"UehK8>\}44>QQF@=$R^稇M.y) ijdHmGVlƦ2T"mġGXC,7؋=ޱ/23܌ .48vExsx@~!AqL#K)ioφ'#(YqRByY<`['Yj2k$M2@2[ Dzjϣ.I3.)/+ e:Z'\؊*tI01bQb 5 sD K]7lqjGIYf0[l,,X2\DW̤g7+2 {&\ETP)Ԃ^¸"!jۈM U͉DS׎`l) 5І;DTeEv j\ƣmm{ƹ$.Ta%g~arV@_\7_ݲ:H5UC0(A\oFZ@az~`v&%H+: fQ}-,A+$=2"Y6񸅾`'ʑ4.z`?%1 >08`k?+Kk31[J,`7d77&qWUdqlyr@|DaKMm]6+)J?܀XTh084l}sךHrdX_ݛ8;OJV0 ,Rr8Cu kou E\KjdzRh5Ƈۿ^xcTL{胉]pDEQ&+]t;Qdh V{m%Zt pἷ[5O(=>w6KYN؏4xLzJeŊƹ$9aH| g[LMZ]qRw Vd὚ION=Y1%Zg`% XP RҖ2^lG75&yz" <$MByޜjӝDzjB TT5q86, vr?Hd!#` | f#I怲=C͎5}U8=Q 剱ƿ1UHDbcsN<Ѥ F't04_\x~ A2Kz ѷ_ `$LB4`Fw2aFx0qGU\ M'K}1[:6b=A5,4>G/0D?b4cZkfxn)+I5ө5a6Mf_fu+s  G`?U屧~j;O'7mS,E/:HX,G$Z4xM2:}Rc,BWAɫaӦڇociS `ȫDWMWh|GYV4ׅɂy)n1,BV7lM_3[Vi 0B6ECT5ۻ}ogǛh ? >Ӱ<.Qܾg vT Da|?Ok0KN2R@*[UPt5O TQx(!Zt+a)0 P@cHxۧ scf;^Tl $0M~bl4a(L3ZTzA A@ kwb:}R(S@9hG|m-P#^gGv˾N r>opl,80@{ϸpZ +c_.o~/ϡ:u⊌:D [P)21EcI2Q&ŗk6m&@fбV9-7YJ%'{Lh7:x«H;f0٘5bnVI/a"ir" %3RH) RlHC`8*1qXjޢYk CVViNVFAԈNk6$:? H2p/͖ýYa,{{r{NUNbW4:eMK0<;dd̖c85z 6K#8`:9C=0 yT_ s'>{H OPz>4tQ@+BDvA[>p}!~N`Eo8*0#?/$-NC-FvQՅ;J_ Y-!n*3Rb8ǦA _[N (lq5V|ZH)&<&uSl8YI<&(!30&]Is$Ub!zGi5,(R+b?2ʙ y#IY`\~֡n N GsXd2kyic\yN!{ӥ4Dk^\iJGn0<-S17iQon껺iqP5w)W#.?eBAqgJ[/Q>Y;qWp٩l &ВЦpg DTRj_wL0\AV|(Pp*Z欩׶(,T:|Fz5nop 'Rg˝zN "a^ɏ1*-ke6 | j-ɨnzdYy ; ^5yD1շ knX|4ͺ|Q cϬiCjN'dT\Qv w1{e|_=sMDRdxYI?H P>mmWRZ¨Y;"1Zi lKMɯvon,f-i]wїhsUA*6@GGB3|ADԷk3vnx.y0Y48I;I*, At-*Tԡ4["y"fLptHθZ b=@Md;*ewc;N0+<(ͬ=c:? o)CdfH9}u`7|#ƮST:Kr;#4yce"?23hDCaK4Mzh1%w&l $N̮[fզj`wH`w&>2Uf?ܔj9-;WY_lCNX_EORCW/(zs:U LU-+G>a1ND'O4N#XsЬ2 Q\`1[d"$x'5,jOMu),kk6{lƋT${u F7t N9a.Tg=)!cN0c|M ?7E(jJDz Q{[ YĒZ؝L]?B _D&y-I#|(zD֯h[Hbdd48+֞vtzVݽ,>|=]ܣŠ=Fk %)"#y0KZpv??|ȟ[D;)SBz{tm}  3L\{FoiZ+{&^SVv -Qv:&-LA5X Jf5c\cu :fi}&IELVRO@ȸ%}'Dh0CvvCz3@"+=U{@_K~6ty&SG%+Vlne=j}P!惨(l5Ҹ I%BDGk}mi V$ESA7}I[߱6r\oS hxO_#kt'8WRaM~N/<:FұCe'ĝ4+*KaGY^qcc LSFB(@GI *q>N7>y=4+Q^=hH𔠚IUsmJ܀Jĉ1oɾĕS\ePcN5h`#Kfb&:Z٬i#b lҪy+'}͸)훦[ysS(ƠywۦbY5ѿlcwr*}[`&j}D/@t_onpf}tBh;4mLC%M#ni+'e$ rP62 H rQT ~]辡!EԐ0bUN7,r7=MUw*SlW;'k~?fHW_~Cx<bnky;$յ&BXJ"r"%CKQQ0ShYU7K+BcEa̾3u0YK?3|<^g!ZG71_59؂B6i0cpII8nKA,12C xO?gJDtyΉ>`Y9н[Znm: Ø%Y$.$7/n!5DXֵdž]%C%;|Z`R eIMm/-x4.BnL} (Tơmdbl5Pu<f D@"l!Q# \&- Wb. A*0Eg T?*Bê%Q4zIMO }m"ʉcN zlL 2}MYxU[URY<[tڍu/|Z–l^F?f5¹>NNbPߩvNAoYdIQ+pwl =lz&zt7aQ&PğTu|i|ymCelb# I P)m `rX?":"nM#b@Wjw$} KN D_0V>,M4Oؘ{~AL#¾F}oRF#%ׁ1M}s;?G "lK) LO4UNCzȊQ/+Z|+rT4 5<$ErRA_.}$F"5;J4 ؙJC z!GgR{>c؍Qkehh~[ 7IқOgoȴ9&͈8ѷ9R emw]S }d ,q_VǑ4gH4d]HrDc ?ak*11 蝿?4OaB %"+`$Lo4B$SxCJO6ɵ> !e_,Ɗ^Re3,t0LǗȪ~.J&wu TX{p~1]gozFnyHOg H. lNo8va"#n~PM| kG$WWdqT蟇N{84dĜ2PGrH)†MjۨMg \|8>bU'h EXL\ŋxTF;w Eͯ[&3?*ҵo@ϯ/Dю"<[O{@0r/Nd$Zfa#Y .g յj\ p3o&\!Z "R 18';WdF l ,d``h{{ch`V]zsLWEUI} ͖1Qkq5\xxcFٞ^c45稾o\'ll ""(;{ؾA0.$ {0/.1= >UYk6Bvвa.,m*?-+n3U= 1?.68QG\(B&? vT>nWpt%haT_9N:?(aX^sXZZ"o(Lj7#2J|պRdi!4geKogaLWj y'r)EJ$1A)B6ft -6]fTW&.fur||-˚“7uxdnql8ؾTegs1ǚ=Y,.G>{21Fƾ\Of*BoJv\eb]MgB!9HM|߁+DM>/a]Ǝ:arp(K~:HFFdzi n4&Dq[ˬni@1ljʶ9o0nǸ7qXKiFy|y:>5$R#\Ē|ÚصdГ6Xxgұ4Tc*ԗr`JA D/ V2l/*%e%?Pho0,ğEIIA\n8}RUM׋ X@Dj_h !('膀|HQ螕HKY?-++8k=VEֲx2An3+e?s}˾HfBG$gf9Y!ة7l 5)|O*ì[aYqmʶc.?4qc)S{ ;Ւ#vH{'AZ<9NǐdyZT8{0BHTh M>3ӣqD,|7k䤧$'"Rڐ67J&d3Xh}W|n4!&֢ضm3#6 k]Q!>A6Ef)UK6)hD`¦D J9U5.̘AY付~iH-e^$Q1%kWﮄYZ$u7M 6x#q(, ×?,uB=muy2mZ۪CG@Ӻw$Af!a5ה{(yS6i)+ 쪽V"n@`[(n_T蝽ͭjwȹ'580ϋQ(w+q C˄'&F ibs)E L $GEp8]`3h7p*+k8E=h: o0-tTq@F+cL1xqPY,3,kWq'1l/"&1w̌Mf+.wbKMH,.5cap6W")!OWgFV+5fU7bRh rXwz^\0\,`9Mc(㸿o0 % sBhe-M_?c;9:It.o2#GsU>׌Al_'t[40@σF#+_!UT=TtA] }F:=&f$l~f8]G ETql1!fSrآ*-(˧| 6*;dAzuQ:DdV tUvl"d+1 BsWq-=;aЫB),јJY*.},7<%A|,QZ~&ksh^WP7 G^,# SJ*7 O#.":b8.;;xw(R'xQe t\XXA:Yv"xKٿ+\OKnplMo 5|ǡ}A_蝝H&&NY;<6_ltq H`baucb=mB=UN%",'Vz[qX)(&x&s1@Ir?9GK=RPaKR~T 0X$3˺JF%Ē>N{Z(B*2.i}X7(Ke;ڄR.W|~ʘ`"7,:/6׎fɧ}IiN<|!Ad.s{B 4 /tĝΘ92p㏅աiȀqH+]Hu>7)e*Ym/A"h_i;9$4PI-]-kۻׇ`H(t%QJď7'Q 茄?ѴU:S2,Nʖ/q•m#*NHr0LK ͍8+r()I/9;Z?뤻9m%7)rcжޟN3z8|=1k*)8N\Q@:GsG]LVFĒgMJYuCHLM%ܒd:޽d4٤H 7Ll?d5(Ay[it alhyZr%hpf|eʆ|T?Yldh:if3 dXBZxF 9ӳI$N-gǜ9* T?$TEA!2 E,ojsx(”zچ~ "Mt8D@JL[n ApXߴT M,ysO9}NWm~@}A:32o +4{M [ {x}irRfVy'oa[-SMA -G:.oKdd0͋hascRF!M! yҶm…Z۩x_7vGXV+;G\v%2̢54`"6V(BcoRfnͳVvF1J1x5XL'P2Q0]u}9HVa#E|ƀ>|Ծ0ȀZ+ٌ4!f-’I'V1,@@I:@x[y7~D4  O©0drSF0dՁ&?4I_$-+[朚q2GMms1.Nxܻ۩A*> CA lC,Mb6'K9D_?z6OB"ϕ_~aeNs[AR@ ?^_CJ^"ۡ%a߹O@Bݿn"= ;!QX1/Zճ5r2f!﮶ӼjldA`J_G]g҅b-8q [ט [ՉwMȄY7T5Zc"̻̮gkםxhX S+62vf[?S-9?y0z *\UQ4sVٛ*Dƶ@z1Yu{uT asjB&9X+l =:/g)YOW06S]PMg}Q7uYRt|j`gO{mwEOcfnEKq`RE<_4p2$d cMU6_>Ѩ|o#J?TПWPFvbPr n vLu(&R-8:5'A3v{+7A6L݂bt *M JW˝먛hrf}s#?E1FL}#4|Y:+[vv<'&p@eā 8]I0@gXU4y]O;52u;AN,ZjY ߯"w:;g\2GEaEm +MnYkkCb[Yݔ$YD)OII~G5R#hZI3 8zk%r 2k6rV-'$mk{"^ T_=tNiwkBE!pĻ??@2hv=D!]̦\_ĐPNS2v^ɰݹvOG?'ģkpN:|V^,p2 Kq x,k'1WW,ƨVi{U@w2VPYlӘiaQWjKꑣIٕ-Yxr%{B; \ՐH&4u"陋p5 S/+=bJ}VJ͙MGBGӳz~> z.>\4&$뿻U1QdSbyG4y{)YDPZ:I2>y<0`P5tǨѥ3x,6I^N1 <^CrXkfJR,kym zφ٪m'W!. }NT3?F/%$tM,q*8İ03>A(RO3h54>x"VGb q=lB̮P_HB{yzlAj7j/>-nwS=:vDW0P;1sr53gO(,zq7T7 @ Y}XzZ$1!|Gf O~'cϙWngFU$؏yUżQi%ǜ1xhK~]=- N\?d};% WKH!Vq3<lmr;i; = o&T]{m9URp rۆ(*#%5YجTQqu7(W"_OYcWV PPXUp7eMwԨzĘxmDEW(Es JKJ9t 8XgiJ7-MO[mTB>`7$f>ʖI И)b$N$8MY? V 0i͌ڇR1_MTkPxԝ fEh}n{]\B0#({@9p spMZP'pdG.K1{Ծ35T&w`qr ע:H80$@67Aco3χ *"{5L =I2jm^=%QWͷT~~}L :0Cyҳ&ٹ~ "/aar]*:d5~a6qW8ˬ: P|FA;Z:LR͵7BXOL@փao'a7*[4NûaO7/1Y`-R:Fڡ4FP_ֹ⚐Q^#){9O~C_D bz=8; G㙔acʴ6ժӭN0̂4 t(hW6@WA}.;C`}_n~'VXœY7گ pl9>S(6FJ>&~1b ^bi K+SJ]&9`H$pW%patࡒdn^,}xbV 1B7m*޸3BMyq05BuwAq7}~W ntVV9X3Zd7יbx%:; sZKh^m;Y¡xsk潝8eׄhKD=Ըs%Սuڊˁʄ|)*cʊ;M-԰^Ѐfg)w PY"] nO.< 䡎]L hg0ZYR Tu%]"6Udwē,ZJqEhH:mzVsBpsj_/|6-c4A0J#{j=SBr]FZۣ *(8QJ!-BIww!ٿwV\7Η<O1 B͊Wh?h,fYdjzp½vj(t,|@E[|fN8 ?7xs"6m} Wy"H݋BeC葽t=ά1,,?H쪾ֽҊnЗ %LEϑgyOh Mlױǿ$ƼLW6fdpIA |0b˫Q9_ݣ7pِA$sUh<w϶]?}ۏ"nԉY#>=ee j0!GT_⮎w)*k|ؙM6U#WB-Bզ\gh(>H!MrSd5WE:O]Fb{gM-[4u[9!ر&[k/#ˀ" a ̊{,{@,{}<苟TOيwD|L&yo1@"Іh pA''S Ѱp=)5]5 FwHB[&ѝ5M-uR7G@G,1) Qse9 +ɹ YyvXEPF+1Y:5+~My9}zh>[;U5¾+j^PWo2Jm>zv:[apګ50A9dؾQ{Bl'ڲ?WlxL_3Br(ϛro#.w4QٷAeoڜWfDͽL%@ouJ;[a9__x?2A5SiZɽ4kX;}ARwcॹ H_%D/yFG4J|q`Y7 ZS&Wè$᜴.A)H'앯߾ 3(zYѱAu=U {2%Оu2a/#ͨJJ'5xX 9קOo~|o9[>+%p/~8xӳ~ƞA#ԩtxCJ^P>"G 0{UW57$JY7KE!I*Ã/[hTJcӱl?ddcϯ{Ob.hK羟$b;'fcw^=MG ?Nq6D1󳃲:\Z_D!@ jU _0rI^_:,稸;ΪY`6OBy}nue/FƝu㢡C ^#NCR/|b\T撐 uf, s NHwpdVsW4?Y%蘆0/@j3?ODGEV@j!Z':YtkmLy{!11A[I$6zB)oL=#JQ>Z/o@^[G P0ECex+BJ H)H+«{5&۰Ӣy0lDÑC4TǺ0Vx BXxv<z7,Ы#4Liɠ/BHMNjcFth!+ʔjo*IRA0 @׮ \V] ːYo} >|R~΀/W⼽ ɠ8ڶ>1Â'f%U) 8OJ5D*ň3/ 8˄E<׸diʬՔ3L.-yӗ=l$T/R.As2~0N"*N7@ ŷ#hͺ^Ωi#BH~p6.λ泥N_u+\uwBnbrϑ@iuk$#TtfLztӀkMUA_G Fr6|u,%;ow^D'V0f$:aLa봂就g[e/9asJO"Hx T E9N1cqnt&"Q;'_[Ȥv{flg{"&DG(~g|u4Ɯ>u*; Ӌw0T G" H͂^e8꿏*kmS:Q3?D+:!=特N%1u#M>QFZVo'2re^R6d: Pw|H>" 1/AYmYpuNb?\\ozI%Yt8}:~(^m⧺FE>Bv(ViLg531L~ BbgbfJN ;< 8'z M69QJas?aup]V_`X-pת'-{f4n:I0D==ü̆^8M's&%Q$@p&m9wp% cّ\&!c|o4z(rp"&~vGg M|%r9V^]_q+O\Kr8_ ⦨N o Y8Pلւ2X8NS볹FqsJA#ݛU1bAq h&瀣M_>y4S۠|mG;N~޺)) oׄ./ _٢oi=9ȕL4L򅹇?ju dʪ$~{&Ue¤\ƙ(|U)Ͱ OS+jUYuXλ ?PVG:4)0/yTc!iR# eJ MJt( Mg޲%XT.Д^qlm˼QY#~aWBCx }%&NWfI7>4|̵ǝ8xLQTelW!!hJIгv)f42:RaDRp,:ؿ*J#NJ)xWkMqYbt1-#%HDKi8Ո^[dƂyK|ChK}VGI$r1 .JuH 1ȵc;=bȗS D|nF@(ȭ`!/Ͻj]F"ӪO =AN7Jpn7gmj*ʻش41Hr0ܡ.M[WeAj":& uBÈ#L:6<1y`lfbqܔݿۆ:e~`9ayai mG>'LvCLK-[G9ǁSf˟_GJPZ;k T~_{LT{.Q t=$)a-r^T9~urJEF/·rl>+gH/>#f\5h<򷂌B(쪅D{;@?Պ:FGj'pO3Ӟ0C- 7K$^x_N% 6ToLfw1MÖ"}`_,4k{S;bmPH >P;/HQ6!s"u=Pl|P[eܹg=:`IӪQΤi BUAL|E]FތŲ,C?oR-tX~Gٺt|ZfT%m`lS-WLoDg&b"!ف<.dx܌g 0Ԅ 3)P'Dwxs)fK!`#!p*x'7T%VBD²b3ͪv%u p"@f)J!x"=h.Q#LJ䬴^> Qz#Ӟ2䖓\_ @ Mc~Cjkrԣ&w@pcۊłCX˒.;m}^1hL0mſIѢs>'w};h"AE1c_3@NAX^Hoa|A)sh%%\3]~&8O x% n}3DŽi;<9h?h Ԝ-U',ahˉFf\ro;:O5*@\N/W.P5k=^MP-eu"7YwGٗXs-7a'Np2&{E^ٜDV52`Ju nگlxn`(ۆmަI=vf;]a[2XzGmPz-Gfȧ$%6pozhAd*Ѓ.=у:%|Nr$Ag3t N" ysݛ<ȺLC0T)ɍ*׻4B'{ey4->~˖Gmzgp 90_^k"Hɞgv2? 13B|-I|z|ht'$2ߡlU|Zt1P8 T sYrU(W-HWP$IILx-M($I,(9ZTQUNb>tmݗ=^ }%̥(^ @]mvf. (G(7>$-`(00eb5(׀fܭ@j񵌙ѯI -y(S7m4?![)_ؕgA8t|*u[~πllvFr,1ץ=Ic㻳Ir%/1y0y7T/;u`ڋc4<?xSݐcmfCHmAk%m{:RO`T U^ȡ# a0+A =FukAc\."a#[USK[p:7ymG."sru0HsLte6^+\ *No'lh_ts)w*ɐMiʃ;{?AtH=JTq Q4_$Qq6kB>>0i 6\ ꪭlత?5)[AS_c7TGDm›+M $!k=m ~lw\kӜ3sm b%9)tM+mBA^|{G*u_7r`9"ļwV;Jެ ~DZ껻%s~R+k0En"ShcS0V^ 򺿹Ϊ 쯳:^—-pF\a#p/ ;X`.%,EyL!;H9ڷFǰ=dy a(_<⤆4DYtdA'$K_8v%3H@ce)N@@~7wH#4,@Oef^f_Œʦ(.x{K~zD|U+OGvX`<؁x(`#ac90Q6^Z m+q+ePב~d@<כIuSq|;8!0pB=(DXQnF/%׵<`n}VC_3)N yΪLaA Pnעu?$xj+C okCt2n&Cх={N~v+]{Ѧy<) ':0;j.F\tp΀T}H6ԦIȆ3`X-4=یfXw(T|84BgM&1:f;Bź"X͋ڧHuNRJ >Dv<ҡI`d{lB.x α->&V;-^ma 8zWgcZyAjԽLL1lgrA=V2pp2Yw!ʀ! -SՀ3.n:(emS05ӻN2K|81]<5m$H3F-gY̕5F2 f~Omx| ] Y&HCEv=Jj4C^D=ΰ+mllF^rQxxjSdNHűɉ#AOҴW-F{?yp B5TId? @7oB&7=զzAH2ƀx4$n hHd򰼄oVi@>Fjטt♫ Ce(z[|ZKogڙj*݁[F.c■K)Ψ!t.N 1_h{DjR_+ֳo$y!D Anj1($ ۸6R1`Lfr_WՃs`TLQ[UCiX&kũ-NZ:@X,¢(| WŹ "c[YD4+Pԯ7荼1ZKܤ7pNOOn5!4eZSʷ)hۙaߦ/7ּ2h"Nܧ$t"ݻU aԷE@Z!zf.+AA XUF!66Ko/#Qu+HqW>4-b;$[P{o&Y~4P.qͧ3pNfk1q ~c_+'%@ˡAD2!̫ixOZ <6J0BM B\cN[*yp qϼL|l29nůdMj%cg"pgs(/a+ ;!*EUWÎ]AنBϥŹzH%9Dp" 3SQxbϑ![r.TYtp}6a>6nMrÕD×]_#&UBȿ!& ^RO4&%meSxTԅJyCǡVH;^/pYJPι8W.=k4RdwLWV}~7Be ކs{K筙#s]VЯ8:GUE@m 3_M[4sDF/"e-fAZH_BI`>]5ǨZQ`%^Jkc}b4#(%{6ca5EU!9w*q*8j+Ϲ{Q9B5/ []s\HP ׻f;ГȁS<%O eZh.co=rcRkm|4"^;/!ZL1z{Uu'lVg10yek4C FV"Xk ݚHR\Fw%h%伪xzѪ rdl&~鷿f1X_jqf ۧlѽY;ݢ Ͽpe[G{Փv(O)zX4w^8q[}fwP̠Hqtҽ.l# thϨs6^YTt=FTC!j gN3ڴJJ$gjg. /䎎T>Q*yg&=N=%J.{ ~< "UakVzZ6B)1k|K\rq2L9'$cx‹U$譀m J % дgO_203IiOo^황pGqx޿2=[`1W{d-;_喵T&MxK⾨s q$8jxaCG(5g]!s; ;= 俠PW aS:e4`h-<1}=/hNyڷ/:0Rfy%H Xw"2 ^9vrdX%益(N2"Һqc_FШIo gfر(uw1ɶcz@j+J/ƩnjSWCW%6nwU8v.k|~٧`R݋y+6>L:!Wk:U-t Y5%06?xd#q0 ZI=%݀b`F~3NFCZwG_j1qŢ["/q?ѭfW xE5m@!24]3y1OXcZ/wd^h;>Nذ[Fa?*ۃ7{zsiJfy6*Dhc*bh' gUUAQp7,>|bC!-3Gb *n4y)g@v\t ħy*i*16 f ɲorC<Ή6x]=v0X%%#1ta$0S=*S>%so]?5zyj"` G=sOeT&{UEcTΒd^_kυe&=3Li2k7/D td73p3 =5cjtZS8`tgRH<~ \c5g mvV!EU_@/WrSG3ݱc;”E"{RBw=BUC FG_`ZUSӿ\z5Z )SudFJM)j%F+$mV"LTȕB 㤔Ii~ }duU[/e禮 VE^Lb5Ռ޹ F{X[rD~% {ʄ! HePRC>`hD,.;C|&:[ND"Ee]/L/c浐YEyɱ>yA)JE+E7s& h)ٲ6?Ի bv^gxVY<#hIwLЋg '#c*AmhIˁjG2=Y"ɑG䦬JHAKsHwORDwͰ C)e~d:3rF iQ+OlDhr`+-Wm>6Fk]>Y- {8*Ш]FWH['C8E |$S;vuʈ~isq\wOvI0zՌwDYI4_3a,N +!h%~,@fIa#F#q=f"|!fIQ 'YC@@ xu|Q<gLvR6B04iWX !b K䛀+e2Ѣc6;)Eƻ!d|\&&yۭt6.a~ ,BQ:0SRoZ iaL3V#1cCܚ`ߣ8/d Jv뤦+J;F'6P7‘tI.QI,cvtzX`IUgͬ;jӢo! hߵֶOI^&ZB9va `(op9C ks4wCF3܅)]VkUPkBRn_)˘қ)8u;E^TG1Acbԓr{E >Sj-MܓM{it ߅y<i>O!{dWP3Q!Pn~1]:x˽:Lwʬlľ[RLw--SUۋh5S1ik~ D|/2˒7 IsOLs:wBk*Ҳ-wGgOS?/9^K A#~40peM՝Ӳ|kO9/Y6 G) D_ހR8/ܢp*joJѽ2ϷD9aD",lpŀrk[hCی|7n jZgK˖iAr:(F0aSJMZvߝ˔{8!+)ME~!Ϛ[g2YB`+bǽ\h\e4u`xyӠh`PЧI^}cG|OЗդ4^0xL9xpeNNeQ'Yr 2T $W\~{&M!sDz cfܩ뇛qdh_";bSj`W1`bRhW$v^ƀ@"x,R$Y5C1%ߡt<+çk:0TĈ %hՀtvXX  '*_E$9StmfY[x=f 1nȅ;3P!җ+FT롘,+Gͬx}>ʎ;?'/6 n`kc&imۻ6mAXd^EgZ)&sT[Zt5>FSTJӌ72 ߱NccJfbVySqmWZX_x/.A9}jMU+6n66tX(W`>j8&TMW}hH|L5W-P YبH*g_\N,8f2HftV[= y1ҽ>_rӵijCSzH6rs׸D^"C{gGC e&Ɍd[Aj#|`xNeBM0 lNd @LWcIXc'-uk Ail@q;%dvL@7n(3c10uXߝg' (=':D3v)c?抠1+=0ϺZʵ97Ȉd, , :E'͌VDYB&4N`ϋ,XEN,O+7a@pV8t=FAi 8 )I渞쨖W1dP5CW3)eV8{ 9G}Ԭ;"6mU~l-Vdˎ8 ETyxGm`ڈR!F x%7=@IEhH~Jrh**/v6zMmt-Qb=9#($<P~yѶ64xFV ۺxCǠ<.K2-mj. RkO=qB{@=d (61ɺbә`dgFtO}$mu6 jLZep EnE>׈5Hۧt_=g킪h1 @}XZ}]qo&k+!\p{ b~~qW7nmv*h]PCT;О$ӿ;|G02S cjt;R^omX8eS,)j'^XG}3*LMOp ^s2joN: C7}9y<p?*ʖNj:\+p&>Y !/G'AIN2#W@.Cx\ƿ L@QTU{nGUexak tUjy_]΃YD{ #r|N{Ⱥ'n-͜w,uhmS)̙G(N"Z/ Vri2azI {4 #Ԏi1sez7 \Xqs@wd[ʁp=Te2u7^EEa$F âl*lCnc{R8C@ue F~߱&H'Ies癧Lb-.dxxJ=ZAB8L:Gq+3{$o> ۄ##+X\O`Ըǰ]9u+S&}A"a4}+RJ  WMO6ĔLjI6XFƁ$͍WzX~~ײַJ?bObAP8.^.X k?]2TJq5\j̗ a{BchApԯph'+/PWIXAo)*YšJ<9 "09FFoe"`rKb G!c.-_1!̷UfT'9̙'.pHu}N^sc'G~#>r3moF-2CmjYЏӬOl* {AQ$&馎:[3;*Ⱦ.<o~RI$?Oxoc!׃yjkg2iY3J򓲘\Qjރ+)_ǻÒBZC9ds&FU>"iH--~'ERv~\ۍw!gb*:7ZR"LN*o~ eÃd?ȭ{O)f[LyU+BȤ@ .zl E8IZ.+ɓnN^_.Ng%Bk9: hI$f ĥjs\ S}J7A*S=A :?q;ʗDa|edJNyD1꽱c=s+"8ς]p-uʼ"׹[9] Qht[\{.w[.=20 -u,,?3X״"ĚU\Lo hD$Pg˛ieK \~I !$Xo.]`j6/\Fa3!҂}R୍NGqΦ`?azcxn2":K#ÕX:J+-``U`mUM\ښ/1A,bE·|/ pghZ#U%XYfuDoX~_T 1G 1։UT3*4{T JepΎB8JTcF^ U@4w~ݺ v&{_+wl=z[|+Q OT7ٰ`~Zְ4K뮨\LOMĬEM*#B8tlI?èHfڦB/l|Oo5;~!T>w̭꨾OPgbA2t\7xէ =SK3; U xzS2p^ h@+|\agx8 [۫tq,et!A7꺂_sDڭ=VĭO4uExs32?/˂惡QQt!楦/-sݤB.tj=vc;^%Y{AW)*lt17Erzb{i(q X1mb,)|]`σ!?.<țU\M+1M 5c)Τ*˖TSJE9A܏^9'!FW<2'":4vإV bu5ג\Jk'i]>wFMomBLu[{^{/s:i[]۪o!W9~▌%q8x("u!OxmxǻT?"eɣ9CUG`g `ոOƶҦ<30GhPO ##X;MTI姰QZC~:a e_n'7*_'.vWa[E?ԭ?)'i JTjY@5i~ D.'5n Q}w? 2IF1>/}3A36 L)SA\XUց :*%3~D{E[O+O=ds`55Գ'=.,< 9p#Z@BvHJ$&2T1(_YInzgoIhhS7|Z ǗIö~qqJ.y@5ڨG9hٳ_e>)cФN /- Vy\x3f(uD_OJh8zLP`mfL/x.IrIG^ - ~ Uӻ1)|(b|AS?:WMá\b3D3_lWwT~ cStl ꯂ5%PrA?~l"Ar i)sESY*] Yڭocb7_+P=ŭ晐9z@\WÀGx f}4LCTuQB"]b6^r(-C^jGz46M 1o֣A xwȊEav[MzPVGy:%t4OVWڧѢvdGӔĞC"t9F39Z#-s)/(>)@Ak6`p5'vA 5Q!F]?@nv4&2EcyYḩP0n*%zKtCvIR^]g_R^vJ|0vwD'3tv: Ds&\ :EzڐD9Mݱ2$4el|)l9_fx:]L{-D3T(7P7)lLF wtuH6ssݲJ3bi7bt Wl֯x"̶W]NE i' -1O¶_TD`P1TlB~Dxs*G[@iZ8R&y3]QFulY.zÛaHRkX@:ُzmf} l`{-G?e@qRrH?Ltj.#zﯯ&;T4w$o`:[I|;'NJMx'/cךl'5r.<2=Jq3K=?'cf],tO^!`Ќr3FmBMSuҨIRFq&N={/w֬",)S 55L PM/.XsX͌u!*#|$TD Nb#sKWe/2^϶rhBT(/Ӻ$8#Mnx (B<}@5Oڣ8veGOٿwr]eb:]* CDȇbK8>NG1j1ƖQ1ztԨr8&-,% 7V)du9qn6< E" hY$AqƱu{7栵4)/#t%Zj16G|ލi{7i,R19n̅Β߲ўg Y G />m[D?O%.?}\/O$ Zg.C.sj;6󯧝H>#}agGtݩHy-iH. p+ܝ.x\lEU"A P'\QY\Gؚ5u9 fӑ {B;ϞqkJ؝Cl\XNU4,@*06߁ U{ VC((?[@o<@fVcgHEM)Yiy?`1IօՓJ~>!&hG#)Q`:,PB/v}34Orz]KC\+E`_q7v~Y!kFi=;a\жUe)(Fߴ昵B}g2,R;]UvMIOG`:4qҰj8Lq vrw U`dc10v0ȭYدs/yUy :!GjSՄu:hĊTzخ(iF :H#Zς7r pCO\Wﻖ's?!|(![)tbE׋zud} )62R5@jXiq0I>y| 0X* a *f豞־ۡE[@ c&Fv`Ʃn^h2'+F/L$囪RI Q*)u]a:HّW Àl(;͎wztUV$,dͮJfۛ7UotLk1V~̂jY3Z߹ܚD)| HH\ecH15im0nZa:McU~<KFqenꔒ󛥞cLdX2Ȇ6p369zC_0qGI0¿XW*yv&ڄd4q''  a귣g`&@dٷ|q3.3DUdSwcu":&{(G6!]gc_h۳Ɩ'YHqS ^3F0UHe c>PN6Meeep.iNs[,C=}(m#xrze\d;7P)CbKG)_-m׶sr[Pa;e(Ǧ& N-HLxtnZ ;撎P,2 ܈b`f_;sEMr.3ܨ>LLk\VΣ/qka"Fɍ"5{B 30".;X0MW%yZ4jI>Z@r( hW6åo#+Jo uC`P)&3XIfxw :kam4ڃ>_4ž.55=]R% rY],4Kxg`u4y.c(@(9)JTcB@+&_2sW΃r0zSc0&U|& KIR IJ&j|̋Ɖ=bGˈC۶j67s8yi3Cj2zN|\oQ ttBzZ Zk ~0*0 RY$K\e8lf^/=P.y~it."nAGӸnΉǧóN Ќuo{Q"7Yeű@.<% ,"/"nSwIFE+r?r\_BI>_#5] CeԄz]e,.\K8qĥv YBEkXXsr˱l8gR8,ն؃v1I#eʡ 'MXw#/^7,j(m,< §O5.g `w`#F V@Q a%uDSho0ddSU L$I/+ዳw&P9(׻Nx Ņ EYZ{>SH :g<[W)NTRBv$Tcis6I󻟸u0)9]^ J2G 3iyI#Gi aůmk[G "HXCDB,T+,W!5+6#b(7\S/], |>+\#%1)\X!VhPKoǶU7¬RG}*f[R$SSog g ~>/)Q2879njp,\}"f3in&vs뫿; y삗xCdҨ&?’u!-|q;bBV_ \Zf 9f3a$[$ T*oLW\2]+Եe뮁@(tK@Q{{@wN8p8 `3Jbc"$Kt-[q$p&$Ž}3܊/x[V\kI/E5wj:a}5Hek֡@uHtеg~) +GTÉ.Ae#s75-DQQ,P~#qrH`n \ڔZI]NI;< _,#CZ96, 6jM:bã@8"J`_8[ͥ?-Fbq`~]nv `Ȉl}lNNYH*nr'ܣ26i4KT +Do؈af^˺J*rVAN(`ؗj&#ָQʫJDLߴcQi{뭫. P#16`ZE&\Eَ;\R1cUK\b(+A @uڀZ>)aZIx(֌thԛ9!c=Cs @m#`}H2~'1+#c@+fշf`mUӁ}=EŽdt Paރ*.ȳ {P5e3`sY:1`FJP+݈rDX wj6vY&'*=x< yoX&"9DbbP]پu*Mf'Ktl?A|RSԞ8`j1[ *Uގ#O,yf+6=`mGgR[Vclw>Du .a2{u pI{l"aǥȮ_t*ѕeQ~HyqC|\"FDMB!s9w"+T\2bV@h t84$$]d"z$iI<^syA5%t(j"n(t9?d)Gd*[캭\(%toWp&P0߰w߃(ajl:5:C멚x}Wwh&ՏdLob>tR,r 5-׳LQ m{M3&r`*I(v%K֓!Zd EXJpTjѬw[<%oZVػ*ra+z#n-0wmÕ=˓zǥSꉐedhY3NI"7j9ŭ ItW>Av@9)! .Bը PN'Y᧬.>* ߫k+K?=XKW]e|H󉚝d ^XܜU\!OjnpCgXˆa?W NPr:5$HS08uS,Тo~*M.YC\-"*XfߙmУQXMc7F4G®, X̯֝Li]z-7CxWZF8Ւ3WUilAbWH\}U{):8ъq'C­ej 2ddYe"Sju:>HdCA i|fz-5AwWA,8E Df|gz=hBA6xW\)blWٿpݤ"3˛㐄G1PNmf;6n1|j6 ^ hФ4FY&[ɽqi.BPX&(MvDW+FS['y9mBY Kܢz#LX{>)8 IKK˞ БC&{|X1&wxD}ӄ+cM^_g\\_P @* Wݸ  ^7]sBft7]޷qwв?P, xVǯx"*kJ@4#EO^ryKNNL&^Eú 7vG60Bs '+$(pnp/-۶]lxLfrk|`$+>LuwvPeZ13Nu$ҚMjp-çWo EVHRyV\E.9W4uP>TKo7tTcu.QF,A;sޚTKWJPCTm "q Sgb,8*K5;%sx@vjB~_ry 0 ByF7ˎX\Nr">hܞA"#ɸ ]KM"i$g):yTW?@Iˊs@Z%b=$|D[hovq2ohR6sdsǝXjx8dK=nw.R-Onrg|w~#TZ}FԢX-gy̷G/)M ~I+ګ`Я6} $>`}q:gLDhaHUʯK?i$!Y@F؞Nͅ KZ.FA1m#dDD:ރ>ə۶JH |>?ɤ̬a7Ϝ yß|[jN{Ixz6 WGBKe3tHOA 4r)ӬX)@_ >ax:{O[; K(4ntv8̯Zwv6:v< e]LD>$pv"etԩZ~}2\# b!%0Ӵ,qERH=l2>8?ya5oO ߲d.DX'`3m[ڻˠ!6ܬ,AR饙`'[ҝB8:~bY"=騠|'=xVCVd[ GJMʅhlC \[[)Ku9ԠLke c ěs'KqF`<1|3/:#NٍKdB$Lzu< (P?`܀-ayaj_sλܯ&y0HbBK Le㳭HFcY"sŧk㌨)3W|Ba06o ƫ=TirnN[0" Sj0IbdjG47 Ɂ *DX& k8ᥲ|s2`" we?lkoeHsIdA<yAڄSvP\t>WDZljS7ʢuWmCrSЂĬڿ9,D 9,_0G5o$mZΈt64ݏ2<62V9^^՞u̬M=lϫ zScd󔶾G{[щ!&}S\]S'o )L'FJj.\y Mt 5_4ȎW".<; ubB>ɉΤ`nq")$ "6Y&p^7AL`˄CqZ;z)l|yet 0p٬T+$c%@WC!Mpゖm2A-5@fv*<^jA\g:RYWN2g|d\5sS1r85wW\=K}bYYyt8bbpNZ9hp+g3NcpR*/HGLNwGU}6Lv 2ͭCҿ ?Qblg-xK4;6>v,^67곀?fmdywAW6lzZ?C#<&vaugF# EN5l4@G$s|9t*9HC~J#<ͳU>`&VcބIpx`Ir*T'35y=v/qvy sBzŤ`3)0up2q|Of)(rk3^"Iۍ |7&P6-~BQjǡ~n,7+ 6> 3zю)iA|C&g^a/Xkޭ0nedF ؈9@].`#ét.i 4!ARi/e?0$XzYE6tKLQ@;\. <ͩ]c`͹;j)@hAdp`7~sj73;Iz?$WDz,8 dwӌ)Y.wۦ]h:!nK\;5zyB7mP(f\YϹL#9&zݩ芍ve {c͠m0îV 3TgJ#\Qb­rXɧ_\p7p^9 TK~\ٚ]*uE)W;&_j#jT Ȩƅ]tN3~ۂ\[Dރr8 Oc6*mK.!)B"b,D0Ǽ1ӊPCfkN5PQ'3X)fjk)oɗ%_1cM "s3pM]n$1oŢ)9n![[;I!\Y*\&}7 ߼>26\c5~xN)VZxCS)Sa6J|=Qr7G  "L04)at~H{3Qhs;P1)d%/gAv a%b;o1FT[$S 1 + O|uRݤP֊ǧ,71sgZ 5m^ ѭdW)tЉ 7Q"WMaCZԋڗ3}nj:7͕Nk^[A4;KMrkFz693PwˢuWAdڠC{1cZňFo)^xM]hME {)/ hKV?ւ1n9 Bg$)<ʸ9b&L8Q}n}~PfzE,%3 XcO[*Dn߭qP4BVd]2 xZ:zv"CAbb _mX"μoA%ԝnДGwF , u2#i`3y7gTn@X۹i=3L>yJe3u$^EzΰYiipY~}F, \F^s˼:LwXvU#wA|8^ 0'i?1|M.AO ٙbPܓgWM` Rdl]&Z}ir98Yqg7;]*Sy+I@0Vx,鳏(Msg9DFX9Z_PBGCJl٘ōd3('>wrfH ؂2am _(䪔ƿ*˺4!9F)qy0Jw*`x9g2kHnxld}̖{#&iU‚&ùDEhoѩW!0VLu Cm`L#wC+G1ý?kBZ(INq2lS;?Z*>_2.C Cn2CC_(!Orv^~NkEM`j.=e{A{Fќ[:4 TQfowv# Md%zk^nbxJ ԛ_R\>ko'd\_[ (8Kf KnÄE}++|Bifiʸ-j%6\uJ~ziILn2v ` L6V*8. [瘘?,#9c ŭo92ai4@>Zzѻ@ )5\\4bYkm6~y%]*7_E԰џ&R7Tۂ y$ζ~6S)H<=R$\Ϝ"D4d8XBQlp9˦ FPNns/[f8ZH kz&֩,Ay7qDav2O,Û(/6Ɔ/+k2igJ-EyA=S7.jck]15O5YvW6E_::7q?q|gRc~E+]LQ |-4ivJAfkVA hPXBϯDdI HM,DۻrCwU=!;'iИgm3JrΦ?~%טu!=g "[gyi/E"kbC{f ko+d`ӊǣ'fc6E!qFM#_7OʏBCTե@ny78 ˶lP4xf (n}#0Y( |Kr{j^EV#D~4QsCu͉Ù`db@ 86g/GZR~=#9#L=#S^S..s_0"`;BWP)G'7K({HD ('jch(y/ޞ`񱮰Ry2>8~F^r_nmn &)?\U$!lxOmFca }[ a{ىHےeGVYGѿDZY<bacDGOKD҆(k!hF Zg7)FW&?KvӒ^N쬋';Φx^WyKE1 H7s"҄,4كJz"cK]sPVC&՟MnD_qk&Zf5~X% ъ1]>d:aPJ6z#R"E[vU ;Tɐ=JcaT\Uh%laEs)lI\bi%'0bchh"mr<s(qlQd#X B*3ĵ,,pFX_MoD5 )y prKO }4Y[)DFR}YNՃg'&^"ʙk&P8zW6t{q䴚Ej.-s̕`/C|ڰ$6ˁwS5ZI NSe~s|2qZ &yg ϳjg;thFq$is:4oPw'IL1+A !e';YVScߌPrR$oJ*΄r&/;+ FZ 9]eO#qWNOEh\DBbj_ YSܬ,[0]/,:TvCZsJ\u͘j-yC?~̑ۂ7Ʈ{!NrډhIGEHZm;oSZ.A^.x~<ֆ73Y M)HU&F6+:K,R|HbxY3T2h6)z x@SkM=d=YB_WS_A֓,|#FZmlJK)}#vɴ^!dWb5h<$ad&;/F\)nű{[ы, N2ꥰj/ -ݣ$`$)ے ]SgnƅQ )IR#bquz*PXv0{Jcsbħ$fVФk6׎LՌbaL°WdX\$':{MQIئp JZHX^-Ϊ5#IwWGӶ9,c?As) CYD%ēi$XJ"5EV͙9:)'#VՔ=\ښmWrEpsͶ!yNbWS瞬Z)Pn3Hmd@$N17_Q@h2 >g>մ%HnձSy Y]j=~ȱaV$x G:P,` l0pu]'U9YG4 KV uKZ'ITDj[i;-+:_Sbyl&/dCK73k^)NX>osv'J a.8ho$9VI+Ѻ-h>kptdUC]VSJ# q,~HԂ$ Fe(/kPns8]luf6vn*Hj&PU.˻zσ.BpłK b凳i7Fyg٣ + _]yVeT &r˗ r$QmP} Adf[0[HGXE؟K\m}o-o9<bܠQ8d  pc*1A+?Sȴ#P&tU\ KsZDV*z*.ƽC\% MWsqn,k$ˠτ<ϥ"f$6e2[j 0ڂΟ@FAPRt*{)76͙ vFT;qm|UߨN?%AIL*wL?A35MNУlR;T$X_Hz|/ ϣ*e1Naԅ,5vاszеD5xL*d,\vbD QljBo2QJ=B{ BS0RPhܦ:cO'.Gp([:ER9IL /l DIf0`vb:6 34'ѭi!-]&C-դ3)A4$Hn&&`GJ 7ʓS|Ou)Oqj+Akv /{Mv$%\ :@U7?_,$jy6)c0~iGZ#4bdțɓ/vnⴷWXDr凨1#%A?*2tL&^ o\SE2M]8FF0<6Ni,4סEcgO2P}JASrjf fŒ; N8P`}?@24 ]T7LTt+$$(nk/_δUP>(X 5|%[n3nvzkD=Y|I ;fDK27DVsSI*ՍC "_FPOےB :ĭ)@%h}ذ fuseYŲbi.{Eh@PUl j{'_"*N,Y ob\ @h*026.[NVsA)+:ʳhiElZBنsq>bK1N„,z&GI#Վv0 Gn(ӴXy e;F~F@sIZV͋2iSgƀT(ɸV,7tcyO_iHGȎ@֤W#`DWs]4Gb:&s%2)OjWXgna .}_PM9,4S-zBAF+r=e̜ JXeh1 ftp=5w4>'Z bIZ !#%nqjj.?w)|x^""{4~zQnS e%N0Q ڤ1-l.s5 QྲྀeH}[ V:>2O:(Vo7>G֭9/_zY3A`7lf:܉ FLSivycBW "`,`A-cf#.) bDt. .5ʚ8gP5zKm_,aN#Ak5'}Opg=Ss$իBuŃ\}{޸y<5TnYfL{r-!>㄁C,4/zEflNd ޲?#I2yW2e6~?ij' S[hLh ZyɮiYjܲfþ 9KV+EJGUX{fCJ2a*Z_bmNlޫC g˜Qo^Mm6-b|z4dʧe=OŁLc8] ҩℲ?BlDT?goЂ!:.pI1F\ƈYiҭ^DȣU0&%յ\,|5Օ= 0^2%J,v-5K) } yxWKw?2w(PS"i$URJ +啙5) ^d" ~e?x-o,^k@C1izU'.4B^Ñx(+[]?KvP-eYa*ň^n x$T 8e!ӡ[)uC$Mlx?͉";(԰oI@|@BV=uR9IiYI}&F}_tQw#LssM*7 2u# m {8I*?AssCHqBqT魏c_wrpMܜbFi]UĠ#nvc* лoÖ| @u{em3WFUȓ=W7 gw6i`K?(JS0`ߖENɷt?sL3Ow )6ǥt]`6 RUs =_Go:~SƁ6)S#>߻1SvY#22:ՃMڈJKTL af<_o|@+`c NXrnJsKZtd cC ({ґF ģS[ိTK2&ՎnkJ|6(zdS87_{^s,;I 9te;V_ގ׳ V֌EZ8h}0v/>WMϐ| 7`\5W,-ID왕'v4;YO7".bmp{k|R7@>>D9nɽ4)7Lahhw(,wc ## ƖFi1,"Q!Y Z:"u}]GO;Ҟ?4qGJ!Kqa c62}<[i;tu@(yr^ ؞ns#uqhYyeXuN 'egen3$2LDVN EyWgڣbA ]JMg3hɯÝcuD}h;`_xd2!b2 Q~Ўy%?)Br􄢢ϩZ30BЯȼ*yHxfO>i7[ mtϚo)Sm N EN_AU~Ѿ1/ dQINFߒ12hm`S3w %%a! V<8(Ejȿ{[ֳ| l8l҆Uk\>blwOhU5}Ujt+` HKJD 3TV v7}9PfdJ53%_>YE1#mTeW(M4U &x4"CIJ/ogꏎ x@6#!Gu=½2f}E!3.*}C%RYvk <޻Ŀ6k+j{I7B8STB"mt֐z@ HкF&[_PN8gq4q"%2_ЙN#QSry9P"(Aw9RTHamrf_ܼ4@t2×q,h03Q@q!'D6DSCV'B}Z+s;\Dz{R両~~p}E[ߟ*0^\wś{Y=!칌#|!Ƭ : C1d0z0};Φ'zL B'c$z웵1L4B^SE%yOi@|HY4D)$ dN^˖P!+L%у@,*3OB>rHh3=P4I.GpJkiJ-%[,>}2aqRb)^Xg]dJD.yvx*")"!_Ovtp'N.eC4|WOxUdlnARD6zA$G^: [%7~c?B8NZ#%>jͅ=RsI@j\fi\)^ |o:E=4)ς sA!k/!xDe<'qR?<#߫_5;OP7S#7Ė/s8b=n}8~YVŻihPChT82MGipzJ.\gDMd#J'OI KĚnRk"NFi$%"iS!4Sއqmo$VXcfZyAxl-KrFЮ Eu92n[a/<.Wa#9eܘ%3ұ`i+(AcKSǚzk%1ٍdHwlAځ0tUBk36h664bv_F s8ymllHݟ#^J/qBۊ9jN 2cw=ΒS\NT\ tTd91^1wKK@< *;1? Mpe3fAt rM⮒[%xE#^YϺ2 Lv kDS/4Ja=wMr2`#kޚ&+suW6 ab_%nn:s&7sČ3ҢҶњcŗmۅ%cJdYogjK3>)Va:H OIϹG,̹/I,bRB+Un/MN dqvV$N柇2Z9bE)s9$1 ô"i[7l& v#R{Q6 yq%N)]OeΊ!8m):X"P^T\nbܸ f#"kZF eZӮ6kr pse]y)?zۖgz4zcdf,(65=U˧jAMU>Ȇ?+0\A4ff)q4@CU*?:j8U*0ge35ţ1{Ʊk)Wj7Ҍj>G<7lvLzemVn7ٴ,I*ɤ׷[v!{Z]=U:(^,#R fK'*?).uj٧ W?pG.NQI) ` h䃊$žGŃyhg(_^r8[N9~ވ0ԇU^xޚ49y8[ N"S8Kua֧N57}:/_kp[ID%d郔9e͍^Q3BK@V}O",vyj!Fxd`FCS|?01 MUYT~&S hh am ^ .Fh͕"#53GtQx]p?'?с[YCl}5wT>lRXc{@|e& cfMQZJ TF7d@U^œ]CoZd-^o#$hocpJ0"!Tt;;o n #UWP0 Kpt8 ml@KIgJmL؆W97O x_[S}^wX#.;.j 53d|a}6g2DHݭtczm 7B4NC Pİ`lC(QnXMmKq9ďIDž31)t̕ȣA A5Hx%DWBP+vDoUy&z[b /v .D:b_w~(dlAבCo( on/ 4$њ?Y/?=zv;I_Dn(%s i$Ǖˈ£6 @>y9|҃([܍$Z``;1)^Gm㩾%ZB䦥7MǔMD?V4gB%L z*Tt+'ct0&W _]]nu ,H mA"{l8L2؟جeuюJe/:3zh.w5u0ۼ{^1~-$q`y!%]`wb#(BSɻ\dzN؃.j$Lsߥ/(ŶmI'd#V0@3R9?3gVԻ5fٱC:1j4=xLFK"Qv?dQUcԳ~11yvaʦSn˂sX^hsݜh_hFtxt@d4:pQOC/dh(L[$V pܖ4;(@| 6ظC/›GV'~;2ˢ"{57~Rb~m`= wJF}"6(d++gDˍX$9r0jr1΅pgφYݛ(duL[.eb3 ͇t鄷=~i%襸[{i㣊!ܨY %tBp46a!x0V4R:u5=mBs>5j_8 -3I.^%{`m}ԍ]DWyS)䝟\d&1kK%=Mʴ- gzo,r< :C{} Qb#9r.`1?E*#ըZ_4kw1!Ts,o9_>X7w_p 8)Cq:oE kmmN1*jR?9=N 1\ᒩ?%lair$^yF,7ߊml`4 ]6~S)gV;=|kq)ۧ}hoPEjT*Z\#lFQ/=/z1ZV*noҠcJDx(d.gM~i:'wpnܱ ƕH<5ZA2j< K!!"1< np~~Wo"C, GɦVCVR(tdY }:*R6>VV-Nw`=~s6/\:|3 ./ @Dp.۔1_x*L,5w;:*2~]3$lV?]u2zQhT]#\~Lb#]LԢCEaH ESv!j2/Ɖgˉބ^I*GAϚ'ZvܭQP4T|^Z}"JFJ?Q`sk; Kq޸ [FX,ލ˞gjݹhI)qxS2҈*~{wRDqbouMFN<(ڴ> Ff@ :U$pJsl_sN455AvjkQ+EA>#bz>:A:6HH¬6 _U!$\[!Jndzvww1;T~a&:֚l*T _ 2>P(#/IK4]r!/^2-"% h|t\Ks&m&;94*5TV&2 p &Oد$U pP9V!N3Ѹ<5W+Yx>¹",noj3[z[I^J41p^gXz{h3ԣlEК҄&V>zo֯fBA OLT6v“3m}a}E)?N/_Ta E S˜Kn'0>b&۵H9ͺ#ؗWMwrNi40mVLDh/tiY@}voK5.uwׯLcO~3I&m wP{W !pn=cd3HPO/EI 8 N/qW]T8ғë=آOUdje r'+Pأ4|mRM[eiaj^V8͏Ym~|Vb؄,.U-CқI7%MIi]ã\]vJDvpͲH+#:oh.w}i(0 ۤ3*B 4C|E5M+1; CU]=/g]7*#b'+Uŝ pcQ1L(*9SNѯ)i\~ 4oz|¬ڿ:yML͑Lle;j \j ~  _;$9#Z 7n0 l% ګJX`Ќ?5K'9ŴT2KiJݻӜXӑʮ?dV QB0]6:GPW7ea12^LKxT"Xΐ':صHʠGrMr ['ȋ׈^j2"cKlfٻ_Jԁ&3f~f6aXx5ߎśؘrP8VKQbvx{)] Z e` 槲D㻶ltRJ&z^WtRI-vC[8#tLrNsZ߅K?nK<*8WhЍg:tq2):DkYbH6]!!0eXhliǧp :xn2,/+'@l_ٰS%T~ zrr(-Ɍy9"܅W F;mhbtՆ+ ǥ'@kn52glSJ=x6' O!8eX hA]+:En/VГy ATxlU~L5)ù2;n^y/+Wk"qNG4Ri@8ksJRcԭJ\ϭmJ6!h> h9ؿ=׭~AA[h &u&N;)y]Xڝ;V o|rj ?їAy($(qǠA>j..'yɡ|'U~\¿IIxV>{AjN%@f&rI 5:^| U_ WZ:@E~LQ RG /^IUp :A Ŧpt5\j,`Bg[/k9 a'#͑UUξڎRE<*Z֍v IgV MRss/I!лlcXaWR“=Eh<G4lH2ϵ)DBpgw> .33ˤHn"A2!37K! "\M0Az%^miJ*'wt\u)JVfLRPˏ)JvGgu@~xOZ8;(O5reS,ʷҋGb~ <(!O !4s[ݫͧ.)+ɬu^X; }d٩8;C}pޫDη͉[JiZpe'=Rk^_e;[D jhR9_dN:AY>𓍵 ӐՍ/+/z﶑5'2= gH. Θ$ pB%3K<'Y/V낒S͓q0qC3[qlMa^68+|8eS%jN;ƨ9/O?եrg՜PnUl13Bxe;qC+ng?֚dp_R8=ֈzf>uǻdb:VQ jiHԸX}uְr_cxwy= 9rW;GK5'6BKIu7]iFf5|ao)5賴ӉT t `Y[0DbR,M1vq'@6n vx1!.!`~U,[z)o + rx'ؐI7̟$kItznA{Jvɓ]+~%ջرTMJ͔Rj{욈$C~ t@x^Hz\0k"I)R{RQx]- vsyPԺ@N]t6Dӡ#0 fwWshF&y\,n@a $Ƴ)#Q C+'_0:&H:nٓCIh_zӝrF>_Ys?L]x])1k8LQWI8xK'͔hds7oxuGP'HO4V CcF|q{@FAyktYQ CLTb=1np?BXdp\,7v߃Jt#6ŹRthf|((oA=B1Nk5\)nSq2hxvsM_ڔXߡt?7WPRnZ{̹*S]aK踤i@B4C*#|^&F)FBO2'}+hiy:M B$L+#k87F۫L_5G4TLTzU -/a5pJv-)6ЈT/-|iZ∜KROp#B`#la"XJtؓp0^G(~3,m,jT8$E}j`bu?o0ڜdOnꏯS72Ȼ?㷳M ,~U-cXZ{.'8kKv'^,<{(J OyE XqT5F/s-F ``-Byj,]mx/9 b]xQ{,%Og"Lpra<cSYMwt[qiꚓ]mKNfH㧑ZTHI"f]5$zFpAS *-W#_j^Ց)(4YPQǤ1Ѩ V)l[[6i S+[|J3hz>,񤻅D$ q_ŹAdX|!b5>FAf~1UxR&0H'9\ZZSZ3~Lj rίҭM)}GI+!U!VcR1h>>GZF& 'Ac3qlgkj|&aLar -Si?ZMy'r;m qZ<ӹAwbnYQ^Ci\zr<ۏSyl"7Fm˛ЫsXif7ZW2˄ ͪbH3d?[pOWX=x cA/ {R@DxO΃I0$i>)Ə[II0 at d-;ZۦvS|K¡ 4w@s6 X H1]H92pCI=Wk6|(r}0<5RT(2 557hǥҌK[z/|Q-_*I}(gd.Ӣb i0bH̜f\O)I>5|`+ٶShDݕsL\|H*1ş* bRW9XD#^)kR,?r=(7V3/J+OR&xNФv$[sPoڽrS?%I1̝oQ?`UM]#严Hᓆ[>d'ݏq|K+ c?8z0 iO'fgrGu&G qiTO_2B1u7Jv+ bs8r;L$e`"0]:i:wT ORJK@zt(.;7`1o4'Zy ;\$ЧBOhxҿIho;(09Pu 2z Ž-nr0yJK^3Вd$#TBY?u8FEeh7qI-Wv2Qѝ4K:YͿ%"َf; lF\b䬩]d #_y (KѰo1OPO.y% 2s]KLI̕i=#V%P$M;AT׎WUx89|ҫm}i7Yx)b7gޱ!Y$ood n^$o ߎ*;Ohl1uP2p[^g]N.)!P7hُh{<Šu|~de/28}w2nu3?(ٛPQm8C|I!=ِ6fw#JdC%\o VoD c մdW{LC=Әi6Ma2Ũ/kΖWVs\;J7h!vk? $=WvvL|ufA,)p1ӄpђk̇Im԰0f!OFZf]r6EZǒf+wG/e(--`yb;X*e  -֋EKGϡz9 DM![-]5 L3&/RT2-23ci&xl m,6yS#8!/FzɃch!q[DQ,x!Wz< H_/^Ƙ6y9k NvxKkto"z@:9h3l+TMa,Q;b0$k_&,wN5'!^S 07.}%\#I`':+7.e0՘V{}헳[O9F"ܔ-я:=G>['^#a^7!S~W@N<`/Z2DVxc4 `m<[pqC%0PxIXOV86"†wQÓ8N~' -Z0Բs,/KI:nHjpi·)`6χ ^),Z!@gbp0Ed9ӓCJn4Vw*ChM +Z.vnWCNDBzŜF(O2_IpgME‚,;p=i=MB ]=W)U4v san{J=(^| cnwNɚٿO=+Ē:,GR.jk?cv{hY 7w/98D~ A4 &}XJ )*7B.:$SV􅴕e(~$|~R3L P*QY N"2O=R]*6_҄<.Z?߳US^VƋ g#1«oa`?qz\ ,b[kɶ zdN6inOL=l5 GĔN"}1W?c@k2ZX ^iAf3ಪduY &؎vsfCľxE@Ȕ Y6§ #,&vK֮\wH@&-m'(90Ob~'wYJ/_/G̷R'{{Yxj,b/&MY[I/?<6RiɷS\3-xCJ0J.۴QLl˜>JNKo!Zc25!6LKJNE~QPXb缍Na3sxڱ%C^鋻.P:MhXA\i4AC7 nJ5S (kw1wIscDh/޷%h  JJ[i7銠s\]~bt@jEDuUv7@7Ka`An,~JZG{MfaGzYKrxٯnhh+~" ƊSTur,֨23[47&H/߈qGԈGn xB0+U3 *)/uxĜQgڀib5u'>sa]խ(sDi dx< ӺQٟ1vlCuo\X!Jƛh.0tEQ%zS\,hH5& 4,&_ة ("4 p> (VUp; 2/[ŌtgѱyiQ45i"@0/Q_sH23RTavP+d1x)JnYZp@UnJ.?< Xƾov.~];C Zf̾cH$׻,>~fz#Ia5%6+2\RFU ^ZüV.dMD@!]WK3)W9wے(QjGR6!1u7k ;Wیa62 h7Ї6l;mlZ2!<ebP1K$NK:m&.X0Fw1ۯ|~{3~xd$QA%d)+ e&8fgC&J ϔP(YlNnVz-lD̖9g>BNvFuBZ.|>7Ma)~4kiđm`@Q (u{KRF4j3&,oisc H|> 8׭49Oddg%!'EGFc=ŎvD:|c1V~Аcc/14EoQRvQ+J?:_gaXFY!qtY W̌&&;v\u xzwXo_lɡF#cPG´܅;S; `Qgؕ9[?s'S󓷸 WTA*R <2agÂ"C-ll+~ )@=xfԯL݇ :T^o*;Nw]‚ƫ /,T 8Ӏ+V>og*Kd)- >,AYv~*.MhL*,J[\㧩D @<{ ";6Rz9(/ -fdY *>%ٟ,((a|CҊ?X>v-ٟ?O¿ N+{(IjnCےS^)S6dS)htmIQV.%*rƱ>>7]K%"S=ě K3O^@_|{ FXa:3fbL;> օ?L/plg"BTIl!׸TVa VȤ-}ܵSQzR])71Mqq4gY/ZC nJDsѷ)3 3ĜEPe M;,珝+>i5WvJS15ɽ9bU5(MyNW#%{; {zl4 cQ?Ai+} _.{Es[ UϤ݁m7Ev%h/v)4 $>ǃRWZ^nVJ&9M<ǟk*ái#lA5.mT?z9.{Tiqr6Q/e1q8zYGKFƞWN3lp!ТL` gZKX4L liZ熀;PU`m2M07=wV!!N2=_y/$oap%橑^ ]Ln_3 "_x̡tZ ӜuR`gv9тHjA:h ʜ Jqh|/^OxDt^@5[9 o=VD5VI y^`lX>D:6缕"~WU뢬粞5vƮv:,T6uB9B%,Nj;5R7mL(1aۯYiR/.`w$k<׃m+rEhAk|a~.t%Є&V2᨞v|3`k]+II$-7sY{mܣG q7?3ܧՆEHrk :eqɥ < ՝k~<7o~"57Rv!LBuFz F|<wy/mPQLijw-ƞKdjigƄƈ\uD?exro}o3>n?Ov_l‰Zس{Y('-9Yb r"fLEY`O%|KHTP&9dZRG-:Lv9-g}YB4, S񩛑'6ؿLF@ωhqhKG#J*3'C Ec#.Z畽e RtǪ`JIc=%E<& 7"M:$cEy N)V36,V$pm3=&<5PK;kkws^f2,:fRZ>z]X&4ƴOzWAT1Rw@2O׎OiX)=NT2*lǢ{^]843Mz 7kdqD2UDϹXf8U |2$`(nYYٸoQ1b\W8B{Y ~{7y+y"$)$.rXv)!a~q'7ybq V\R;UQfJb6<{|f+vcv)'lE_