sssd-tools-1.13.3-60.el6$><{إn䡌,>2?d   A *HNTbb b db b b b!xb#bb%L%hb&'9'9+9(,Z8,`93x:,GbHbIbXY\b]Db^4bdäeéfìlîCsssd-tools1.13.360.el6Userspace tools for use with the SSSDProvides userspace tools for manipulating users, groups, and nested groups in SSSD when using id_provider = local in /etc/sssd/sssd.conf. Also provides several other administrative tools: * sss_debuglevel to change the debug level on the fly * sss_seed which pre-creates a user entry for use in kickstarts * sss_obfuscate for generating an obfuscated LDAP password[)'Ox86-01.bsys.centos.org CentOSGPLv3+CentOS BuildSystem Applications/Systemhttp://fedorahosted.org/sssd/linuxi686+ɤKSA |5r#1FR :bo3^ 10m:+}MHOt ?tH dC A큤[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)'Vpn[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&[)&6e0820314ea3ec7bc18b1a02ec3301dcb834a52ca671d60e8bbd6e8dda29149e10acab9502ce2e73014692130c887714ab86d0c8455e3ca3c60654dd1eb87dfbcbe626e51dc7fdf478397557ae7adf0452f253bc11ddad6cb89d4d5fa8fa20087f9c819356c2781dd47f9abe0138a5b58c00d63fba576d13b27ca1040181516e865c4f8b05fae82b77e7c3d36a6b73bd717a761d707845344c65ad8b31ac2846074ea22f08e186a8f16066958ff1cb7da80f4a744e9737ad3b619beac9b0a45e4b5ce8776a762c744f1a6baae5545d31d9d4bdcfd2db99a12ee83cd804192a1a38a9daf34044a114e85b3ee4965a4712cadb8857e38b24ca88328bcdd9c8941958dbe4f10a9270f7343dd9d7f90bb6ad02b51363ea969a23b8c4282e241ea075d09230a51dde5dac102de3ec991294200bd38d2e9a330a9bf9d551d987b0697948f560a1d2c5b425b6bc3cdfb439f6ba3335a7210d772475b29fff80ad4dc2848ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b90312faa0bc15ca0607109277f9e39c1d5b3f8f870b22ab03d9cd843dcb4937f23c898d9b4aefa781bcf8722e504fc5ac11f5d42eae2fb68dfe61122b8f98044a5d3d205d14a01e31bac7159e1ba9e65e1cd92e17b72af1eefd70fd8129c07bfa32a37e4f153c7948135315a93ebc523b5da3ff74134e37db1e58707f69f285995751ea01896d4b36ebfcaf460822c8e1fac3591ffb8062729702047d1feb185eb0306a72ed47048c15ba94b54fbe85fa0488662543060326e892178173483a35c79a25c04eac19642dd5c1de9c5715dca1978179971b917e21570b05010d9a51b6cbd6c2adb56fc77c0cb0e14d4575c99b507f6258409528ee860d6608f5a5f4e68fb90fe31e5abfbf19ea48c634aeb350f5c77d359556d5bddc40dd343e3210c50d992b8829d02b047b0aed7fbdeb05437563cb120618042e1607c36876699b64bb8e9a900564768929f88d57e798bdfdaa250ca225e051773c9cb698bbf9cbbdfce91ac10376053bb29a9e7be4ca3d0b44a5ee1c40066c9053b648581938913e6368ecccfc089afd5d2db3d4a993d685c9e24df43ba9b89905ef3da0ee317577d7359fe269dd50ceffa06e6d8b31d815fd3ffe14624f40d30bdedfbd186e803c731156edbde991952c524cb249c9291fc6f1f32a72b048bb8427ec889c6c3be2ae986e869623bbd719ab0b78d7f55a1c56ecf6349e6d4bd126636f890b355e35139fff8021748cc1c1f839ba681f08b2574bb6c7a5c95ed81a2eaa4f92cb927c5eefd7f14a2fe6dffc5e3daad37726aa63767189e2c6b14db2b80a8786fa81166f7519010c5f1a629c2b526106f60aa71352c22deac55026791058021208a55563394c60ede4701240cb3f1ad645d2f050d3fd896243dbbe21d0f918c1ca668ae1442c3ddb536dc94607fbff11a1653b979831a1ae879514a37a3b2967dc68bfa063fbf3e17dcf7a075908f24983b99d9a29ace2c27dc536673bce4f5c295ce806e2e3eca024c9d1c81c9ae926e676c74d2cf28f27cf696877a1ae201716e810a34443659f203bcc26033c99f1f44f636facad0a96186f185c4d00472e1feabdccccb36026a8c926867926b2f2c7a905415c3762260d12af95929b9446f51a1173bb88ad62e35bdb2a27feaccfcd7d8a24550b32aea3537e54e46866edf7a7b325b4546d68e849c368c0acf4416aa1683d9316a636f7a296424912a8943bda31b812282fd97808def916ad5340ab1201943355c75a31b4f60adf5bdee206dbb704998e25bb3b089fba27be6304650028b61ba8fa12f9bab1b7bbb5a94afa96ba8c6775d4712280211e0787dae108363ef3ba1d60b97e78a532362f0ca7f151995fcb93b3d7179c666a6f1ba4374e98880f3999b0d4c18be0b8c5690755ed6db5ffa1f41dc2848390ce1c1adc16d936d3bec7678d75df512aaa8c65ab05a2360edcc4f8eca8c6c7856f81172fafeb7b3fac9f6d2e4fcd7d2cbb3ee71259899900c70a0feeefe148e9380948617378f68caf855a74c6210ef6975dc2076f80092a54cd54279190b70df0e6ebafcd73e1d78c155d693289d3cade81c583a8b861197472ab6727f10207ec4bba8e70931c3c7fe84ba84ebcd657e3aa3058a8e4d1c9d3e47121dfed2cec72d72ecf81cebdc0e3c304edbfe18e7e03a8c92485d1b4dad2edbd20d665af641b9bb99993a41b4706733028b299fbcbe78c8befb5ef5395daf0302535a4b8b38a528c2f5e1447f05fea574c180504982cda4f30526999f9b097ae202cc188ff261fa7f8bc26dd13fc4e5699c549d4b181ded57e3c0720a9a6296ec70ce1fca467a8b2366d359e5f58532643db85c3896c5c2c2d3b2c68a41a713c4a4d055f6b739e2f6e77cf70dcb4307e82ae2b8ad9334c1fcfacf837e1de8cab1147201585bc8ecf5be5e1455af4c28bb081336f004cba4aec2e96ba5e93a0d6e9c554d9e7ceb6b78d89972e86b2f77e4a47c248930958cf35de382e8dbf61346453cd71b6673abbe15a9b68e0e1a9ca23df9475f8a49917be1474c238557624a79130062f62e9dfdb579f972293dec8ae2a4f083d349d624bb2ed68c952191737112f04ed07bc723c327a1cb950c81ebd12eaa17a35822e9cfa00211406f322dc890b40a04379300f907e65a8a541e706503102f4d8a5af3254f5a6f1c3c7cec4d9cbad94da713b12a9a70fa5fd5546dc97fca80c9f3115be2c4add4cbf8f405db62bec3d0a323d50892b5ba8ffe43407551dbd8be7a64fb1e89a335debddc88ddd59e8e10bb135e896310e43b55570617f0a750f8849740a7ce5831149544e5e45a8f85569ea29b3e521f27a3cb1418e8876d29be98db14b44c0e74c4384d2648368c6865b7de8bf97e183dbee9b1728ff2d7e085276f99c941493af78689d832a08118ac282947260339f85171549f5e1100155814458cb6ccb5e4494864990e6c2563b101fae7d70d85bb6dbdf2ca19d730d5587ce1a2b573ef44cc773338518ba1c10a4931d658c8703064c62c50d49c1dfe8e9053e1b7fa95856453a88e1e1cc56ce71772e1f8305d88fd591b2e437681a88c3f49d3ba9f0eea405562aa031a6fc9811410efde0bfb9150ab93167eb0c9742125a7b83f66615b57dc7c57da2d15b1bc49d4a2cab4a8f47af7ededd50cf8a6cf6c809a8fae4098a5d6d24a551458fafb42b3163c130edf0bc9424482ee50fad0ef35016888ee1ca7048d44f71c7f73ee5a535970fa8ad4fe6168897d9cdee7c7fc629f6c7ebf6f91d868aa237fc7eaded2b930313137764a5219ecbf43cb34c44edc46f9326f87fb8486c9fa7474184b14cfbe9a56fd3d94e453c3ba02c7da36cbc5304673d0b710fb0bf7685c2302ef9dda9600b606d122e91feb6e2186fe7b23dfad9d4119bc602b63b8fb841e07302111c6cf39ba94446af50f58e9389102129288b081d8e1273b13c622d958c18edc37fa36dda60f9af3cc4263c599c7b035a514407053884423412536b3126aa677c3994edf5f55e3fb0c4f1827d3ce5fe136083251bd6f207128f4919b7eb764584baacf0346e75f3467f9a1e0664b128b2ea2528ee22a48c7d1b360bc1493fead5f8a43f6a1d9c40bbf656c34abe221fd89740c6da946685148f966c8c378148f13ea8b2353d7c7737a509eeac64aa79423d69dd5e48e3d1ce70b89c012ad0c5ff21e2cc508d6cce293f343a1a9414d42a5e7ba039f982dc70c8c003f6a0aacf3215914efb1f85dc4ad65895b2a883be102f5bffd4b5447d9ece7b535c19112dd777d4d068848d84c51b13fd220519b87d8379fb8ad63d81f1f3a691e1879844a81229da8aa389b6e7236ddce33b6fea7acb7750642ebedf61beaff107e4d53e93592e5d84b85fad07f27bfe720b52deba680abc81b1729a6b6cda7f08b92cf7a7d61acb16d925390d1ce0a2ee2cb19d3f18245647d8e43c69c4b6309ac78ef674fbba769120dabce7cb535c2b0cf880ca163296d752dad7e464d6ad704c850b3804c8ec5b4355c88d8fee9c8b049b55558229481c0f7ec0ff83f557336738850452169ea02047a437e71c085aa5205550c9c5b54d77d51ee2f4e2ecd18c39550b260db95664b1b3eaad40ab0c33dd1545e3eb66c787d6fc4fc8a07428c12300db06f892645e41a5a2c1268c46db363ac492f3eaa69246ae4f4e15e6915f5e7648ce96721b7cf53f7a3f9357e26e15c0c58888370719041f9c5c098919ce2a37957d10a735a02e828cb555ee4b1371fb1e8f2459dfd94495534a2aa3529f515d066ff6b0051d70515e53b3cb52395128c684923c1a86de81bce6f77ade86fef840354705b578b2d4ce19e6df1becdaa80b818c5bd7236frootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsssd-1.13.3-60.el6.src.rpmsssd-toolssssd-tools(x86-32)   @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ sssd-commonpython-ssspython-sssdconfigrpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(CompressedFileNames)libbasicobjects.so.0libcollection.so.4libc.so.6libc.so.6(GLIBC_2.0)libc.so.6(GLIBC_2.1)libc.so.6(GLIBC_2.2)libc.so.6(GLIBC_2.3)libc.so.6(GLIBC_2.3.4)libc.so.6(GLIBC_2.4)libc.so.6(GLIBC_2.6)libdbus-1.so.3libdhash.so.1libdhash.so.1(DHASH_0.4.3)libdl.so.2libglib-2.0.so.0libini_config.so.5liblber-2.4.so.2libldap-2.4.so.2libldb.so.1libldb.so.1(LDB_0.9.10)libnspr4.solibnss3.solibnssutil3.solibpcre.so.0libplc4.solibplds4.solibpopt.so.0libpopt.so.0(LIBPOPT_0)libpthread.so.0libpthread.so.0(GLIBC_2.0)libpthread.so.0(GLIBC_2.12)libpthread.so.0(GLIBC_2.2)libref_array.so.1librt.so.1libselinux.so.1libsemanage.so.1libsmime3.solibssl3.solibsss_cert.solibsss_child.solibsss_crypt.solibsss_debug.solibsss_semanage.solibsss_util.solibtalloc.so.2libtalloc.so.2(TALLOC_2.0.2)libtdb.so.1libtevent.so.0rtld(GNU_HASH)/usr/bin/pythonrpmlib(PayloadIsXz)1.13.3-60.el61.13.3-60.el61.13.3-60.el64.6.0-14.0-13.0.4-15.2-14.8.0ZH@ZH@Z2gYyX6@X6@XS@XOXJXGXF@X@X6@X6@X-X!@X!@X&X X X WWWW@W@W_@W_@WWW@W@W@W@Wi,@WYZ@WPWPV@VJVJVV@VՄ@VՄ@V@V&@V=@V=@V@V@V@VvV%@V%@V%@VVVVVpVii@V\:@VXEVV@VV@VV@VMV2 @Vf@Vf@Vf@UAUUuUn@UmUjUcUcUUUUUJ@UB@UB@U@U?v@U>$U8U.RU.RU-@U-@U-@U-@UF@UF@UUUUUU U U U@U@U@U@T9TTTTTTT@T@T~T~Tk4Tk4T$TTT@SvSvSvS%@S0S<@S<@S<@SSSSSSS/S/S;@SFS@S@S@S@S@S@Si@S@SSS!@SsZSpSNpS 4@S 4@RRRRRRfhRD!R1R%@R @R @RR|R|R|R|R|RRRRRRRRRRRRR@R@R@R@R@R@R@R@R@R@Q@Q@QQ*@Q?@QQvwQkQIQ5@Q0@Q']Q @PPPP@P@P@P-P@P@P@PDPDPDPDP[PPPPP@P@P@P@PPPPPPPP @P @P @P @P @P @Pf@PPPPP @P @P @P @P@P@P@PPPPPPPP@P@P@PpPpPpP@P@P@P@P@P@P@PP@PP@P@P@P@P@PPXPP{P{P{Pz@PqnPl(PaP`K@P#@Oĺ@O"O"OOO@OO~O@OOO@O@Ou@Ou@Oc+@O]@OYOOdON@OLOLOLOLOLO;@O5O1@ObN@NNNN@NNNj@NN$@N$@NN@N@Nx@Nm@Ng\N[@NTN?N:N:N:NNN|@M{@M{@Mߒ@M@M۝M۝M@MM@M@M3@MM>M>M@MM@M@Mx@MM=M=MwkMwkMv@MtMtMc@Mc@MbSM_MQ0@MJMGMA^@MA^@MA^@M.@M9L!L@L@L@L@LNLNL@L@LA@L@Lk@LYV@LRLI@L7@L(L_LLGKj@KK@KK@KK[K@KK~}@K]KY@KO@KKK/c@K+nK"4@KJJ@JJJkJJ@JJp9JlE@J?r@J0J,@IcIcIzI)@I)@I)@IV@IV@I@I@III@Fabiano Fidêncio - 1.13.3-60Fabiano Fidêncio - 1.13.3-59Fabiano Fidêncio - 1.13.3-58Jakub Hrozek - 1.13.3-57Lukas Slebodnik - 1.13.3-56Lukas Slebodnik - 1.13.3-55Jakub Hrozek - 1.13.3-54Jakub Hrozek - 1.13.3-53Jakub Hrozek - 1.13.3-52Jakub Hrozek - 1.13.3-51Jakub Hrozek - 1.13.3-50Jakub Hrozek - 1.13.3-49Jakub Hrozek - 1.13.3-48Jakub Hrozek - 1.13.3-47Jakub Hrozek - 1.13.3-46Jakub Hrozek - 1.13.3-45Jakub Hrozek - 1.13.3-44Jakub Hrozek - 1.13.3-43Jakub Hrozek - 1.13.3-42Jakub Hrozek - 1.13.3-41Jakub Hrozek - 1.13.3-40Jakub Hrozek - 1.13.3-39Jakub Hrozek - 1.13.3-38Jakub Hrozek - 1.13.3-37Jakub Hrozek - 1.13.3-36Jakub Hrozek - 1.13.3-35Jakub Hrozek - 1.13.3-34Jakub Hrozek - 1.13.3-33Jakub Hrozek - 1.13.3-32Jakub Hrozek - 1.13.3-31Jakub Hrozek - 1.13.3-30Jakub Hrozek - 1.13.3-29Jakub Hrozek - 1.13.3-28Jakub Hrozek - 1.13.3-27Jakub Hrozek - 1.13.3-26Jakub Hrozek - 1.13.3-25Jakub Hrozek - 1.13.3-24Jakub Hrozek - 1.13.3-23Jakub Hrozek - 1.13.3-22Jakub Hrozek - 1.13.3-21Jakub Hrozek - 1.13.3-20Jakub Hrozek - 1.13.3-19Jakub Hrozek - 1.13.3-18Jakub Hrozek - 1.13.3-17Jakub Hrozek - 1.13.3-16Jakub Hrozek - 1.13.3-15Jakub Hrozek - 1.13.3-14Jakub Hrozek - 1.13.3-14Jakub Hrozek - 1.13.3-13Jakub Hrozek - 1.13.3-12Jakub Hrozek - 1.13.3-11Jakub Hrozek - 1.13.3-10Jakub Hrozek - 1.13.3-9Jakub Hrozek - 1.13.3-8Jakub Hrozek - 1.13.3-7Jakub Hrozek - 1.13.3-6Jakub Hrozek - 1.13.3-5Jakub Hrozek - 1.13.3-4Jakub Hrozek - 1.13.3-3Jakub Hrozek - 1.13.3-2Jakub Hrozek - 1.13.3-1Jakub Hrozek - 1.13.2-7Jakub Hrozek - 1.13.2-6Jakub Hrozek - 1.13.2-5Jakub Hrozek - 1.13.2-4Jakub Hrozek - 1.13.2-3Jakub Hrozek - 1.13.2-2Jakub Hrozek - 1.13.2-1Jakub Hrozek - 1.13.1-1Jakub Hrozek - 1.12.4-51Jakub Hrozek - 1.12.4-50Jakub Hrozek - 1.12.4-49Jakub Hrozek - 1.12.4-48Jakub Hrozek - 1.12.4-47Jakub Hrozek - 1.12.4-46Jakub Hrozek - 1.12.4-45Jakub Hrozek - 1.12.4-44Jakub Hrozek - 1.12.4-43Jakub Hrozek - 1.12.4-42Jakub Hrozek - 1.12.4-41Jakub Hrozek - 1.12.4-40Jakub Hrozek - 1.12.4-39Jakub Hrozek - 1.12.4-38Jakub Hrozek - 1.12.4-37Jakub Hrozek - 1.12.4-36Jakub Hrozek - 1.12.4-35Jakub Hrozek - 1.12.4-34Jakub Hrozek - 1.12.4-33Jakub Hrozek - 1.12.4-32Jakub Hrozek - 1.12.4-31Jakub Hrozek - 1.12.4-30Jakub Hrozek - 1.12.4-29Jakub Hrozek - 1.12.4-28Jakub Hrozek - 1.12.4-27Jakub Hrozek - 1.12.4-26Jakub Hrozek - 1.12.4-25Jakub Hrozek - 1.12.4-24Jakub Hrozek - 1.12.4-23Jakub Hrozek - 1.12.4-22Jakub Hrozek - 1.12.4-21Jakub Hrozek - 1.12.4-20Jakub Hrozek - 1.12.4-19Jakub Hrozek - 1.12.4-18Jakub Hrozek - 1.12.4-17Jakub Hrozek - 1.12.4-16Jakub Hrozek - 1.12.4-15Jakub Hrozek - 1.12.4-14Jakub Hrozek - 1.12.4-13Jakub Hrozek - 1.12.4-12Jakub Hrozek - 1.12.4-11Jakub Hrozek - 1.12.4-10Jakub Hrozek - 1.12.4-9Jakub Hrozek - 1.12.4-8Jakub Hrozek - 1.12.4-7Jakub Hrozek - 1.12.4-6Jakub Hrozek - 1.12.4-5Jakub Hrozek - 1.12.4-4Jakub Hrozek - 1.12.4-3Jakub Hrozek - 1.12.4-2Jakub Hrozek - 1.12.4-1Jakub Hrozek - 1.11.6-33Jakub Hrozek - 1.11.6-32Jakub Hrozek - 1.11.6-31Jakub Hrozek - 1.11.6-30Jakub Hrozek - 1.11.6-29Jakub Hrozek - 1.11.6-28Jakub Hrozek - 1.11.6-27Jakub Hrozek - 1.11.6-26Jakub Hrozek - 1.11.6-25Jakub Hrozek - 1.11.6-24Jakub Hrozek - 1.11.6-23Jakub Hrozek - 1.11.6-22Jakub Hrozek - 1.11.6-21Jakub Hrozek - 1.11.6-20Jakub Hrozek - 1.11.6-19Jakub Hrozek - 1.11.6-18Jakub Hrozek - 1.11.6-17Jakub Hrozek - 1.11.6-16Jakub Hrozek - 1.11.6-15Jakub Hrozek - 1.11.6-14Jakub Hrozek - 1.11.6-13Jakub Hrozek - 1.11.6-12Jakub Hrozek - 1.11.6-11Jakub Hrozek - 1.11.6-10Jakub Hrozek - 1.11.6-9Jakub Hrozek - 1.11.6-8Jakub Hrozek - 1.11.6-7Jakub Hrozek - 1.11.6-6Jakub Hrozek - 1.11.6-5Jakub Hrozek - 1.11.6-4Jakub Hrozek - 1.11.6-3Jakub Hrozek - 1.11.6-2Jakub Hrozek - 1.11.6-1Jakub Hrozek - 1.11.5.1-4Jakub Hrozek - 1.11.5.1-3Jakub Hrozek - 1.11.5.1-2Jakub Hrozek - 1.11.5.1-1Jakub Hrozek - 1.9.2-134Jakub Hrozek - 1.9.2-133Jakub Hrozek - 1.9.2-132Jakub Hrozek - 1.9.2-131Jakub Hrozek - 1.9.2-130Jakub Hrozek - 1.9.2-129Jakub Hrozek - 1.9.2-128Jakub Hrozek - 1.9.2-127Jakub Hrozek - 1.9.2-126Jakub Hrozek - 1.9.2-125Jakub Hrozek - 1.9.2-124Jakub Hrozek - 1.9.2-123Jakub Hrozek - 1.9.2-122Jakub Hrozek - 1.9.2-121Jakub Hrozek - 1.9.2-120Jakub Hrozek - 1.9.2-119Jakub Hrozek - 1.9.2-118Jakub Hrozek - 1.9.2-117Jakub Hrozek - 1.9.2-116Jakub Hrozek - 1.9.2-115Jakub Hrozek - 1.9.2-114Jakub Hrozek - 1.9.2-113Jakub Hrozek - 1.9.2-112Jakub Hrozek - 1.9.2-111Jakub Hrozek - 1.9.2-110Jakub Hrozek - 1.9.2-109Jakub Hrozek - 1.9.2-108Jakub Hrozek - 1.9.2-107Jakub Hrozek - 1.9.2-106Jakub Hrozek - 1.9.2-105Jakub Hrozek - 1.9.2-104Jakub Hrozek - 1.9.2-103Jakub Hrozek - 1.9.2-102Jakub Hrozek - 1.9.2-101Jakub Hrozek - 1.9.2-100Jakub Hrozek - 1.9.2-99Jakub Hrozek - 1.9.2-98Jakub Hrozek - 1.9.2-97Jakub Hrozek - 1.9.2-96Jakub Hrozek - 1.9.2-95Jakub Hrozek - 1.9.2-94Jakub Hrozek - 1.9.2-93Jakub Hrozek - 1.9.2-92Jakub Hrozek - 1.9.2-91Jakub Hrozek - 1.9.2-90Jakub Hrozek - 1.9.2-89Jakub Hrozek - 1.9.2-88Jakub Hrozek - 1.9.2-87Jakub Hrozek - 1.9.2-86Jakub Hrozek - 1.9.2-85Jakub Hrozek - 1.9.2-84Jakub Hrozek - 1.9.2-83Jakub Hrozek - 1.9.2-82Jakub Hrozek - 1.9.2-81Jakub Hrozek - 1.9.2-80Jakub Hrozek - 1.9.2-79Jakub Hrozek - 1.9.2-78Jakub Hrozek - 1.9.2-77Jakub Hrozek - 1.9.2-76Jakub Hrozek - 1.9.2-75Jakub Hrozek - 1.9.2-74Jakub Hrozek - 1.9.2-73Jakub Hrozek - 1.9.2-72Jakub Hrozek - 1.9.2-71Jakub Hrozek - 1.9.2-70Jakub Hrozek - 1.9.2-69Jakub Hrozek - 1.9.2-68Jakub Hrozek - 1.9.2-67Jakub Hrozek - 1.9.2-66Jakub Hrozek - 1.9.2-65Jakub Hrozek - 1.9.2-64Jakub Hrozek - 1.9.2-63Jakub Hrozek - 1.9.2-62Jakub Hrozek - 1.9.2-61Jakub Hrozek - 1.9.2-60Jakub Hrozek - 1.9.2-59Jakub Hrozek - 1.9.2-58Jakub Hrozek - 1.9.2-57Jakub Hrozek - 1.9.2-56Jakub Hrozek - 1.9.2-55Jakub Hrozek - 1.9.2-54Jakub Hrozek - 1.9.2-53Jakub Hrozek - 1.9.2-52Jakub Hrozek - 1.9.2-51Jakub Hrozek - 1.9.2-50Jakub Hrozek - 1.9.2-49Jakub Hrozek - 1.9.2-48Jakub Hrozek - 1.9.2-47Jakub Hrozek - 1.9.2-46Jakub Hrozek - 1.9.2-45Jakub Hrozek - 1.9.2-44Jakub Hrozek - 1.9.2-43Jakub Hrozek - 1.9.2-42Jakub Hrozek - 1.9.2-41Jakub Hrozek - 1.9.2-40Jakub Hrozek - 1.9.2-39Jakub Hrozek - 1.9.2-38Jakub Hrozek - 1.9.2-37Jakub Hrozek - 1.9.2-36Jakub Hrozek - 1.9.2-35Jakub Hrozek - 1.9.2-34Jakub Hrozek - 1.9.2-33Jakub Hrozek - 1.9.2-32Jakub Hrozek - 1.9.2-31Jakub Hrozek - 1.9.2-30Jakub Hrozek - 1.9.2-29Jakub Hrozek - 1.9.2-28Jakub Hrozek - 1.9.2-27Jakub Hrozek - 1.9.2-26Jakub Hrozek - 1.9.2-25Jakub Hrozek - 1.9.2-24Jakub Hrozek - 1.9.2-23Jakub Hrozek - 1.9.2-22Jakub Hrozek - 1.9.2-21Jakub Hrozek - 1.9.2-20Jakub Hrozek - 1.9.2-20Jakub Hrozek - 1.9.2-19Jakub Hrozek - 1.9.2-18Jakub Hrozek - 1.9.2-17Jakub Hrozek - 1.9.2-16Jakub Hrozek - 1.9.2-15Jakub Hrozek - 1.9.2-14Jakub Hrozek - 1.9.2-13Jakub Hrozek - 1.9.2-12Jakub Hrozek - 1.9.2-11Jakub Hrozek - 1.9.2-10Jakub Hrozek - 1.9.2-9Jakub Hrozek - 1.9.2-8Jakub Hrozek - 1.9.2-7Jakub Hrozek - 1.9.2-6Jakub Hrozek - 1.9.2-5Jakub Hrozek - 1.9.2-4Jakub Hrozek - 1.9.2-3Jakub Hrozek - 1.9.2-2Jakub Hrozek - 1.9.2-1Jakub Hrozek - 1.9.1-1Jakub Hrozek - 1.9.0-3Jakub Hrozek - 1.9.0-2Jakub Hrozek - 1.9.0-1.rc1Jakub Hrozek - 1.8.0-33Stephen Gallagher - 1.8.0-32Stephen Gallagher - 1.8.0-31Stephen Gallagher - 1.8.0-30Stephen Gallagher - 1.8.0-29Stephen Gallagher - 1.8.0-28Stephen Gallagher - 1.8.0-27Stephen Gallagher - 1.8.0-26Stephen Gallagher - 1.8.0-25Stephen Gallagher - 1.8.0-24Stephen Gallagher - 1.8.0-23Stephen Gallagher - 1.8.0-22Stephen Gallagher - 1.8.0-21Stephen Gallagher - 1.8.0-20Stephen Gallagher - 1.8.0-18Stephen Gallagher - 1.8.0-17Stephen Gallagher - 1.8.0-15Stephen Gallagher - 1.8.0-12Stephen Gallagher - 1.8.0-11Stephen Gallagher - 1.8.0-10Stephen Gallagher - 1.8.0-9Stephen Gallagher - 1.8.0-8Stephen Gallagher - 1.8.0-7Stephen Gallagher - 1.8.0-6Stephen Gallagher - 1.8.0-5Stephen Gallagher - 1.8.0-4.beta3Stephen Gallagher - 1.8.0-3.beta2Stephen Gallagher - 1.8.0-2.beta2Stephen Gallagher - 1.5.1-68Stephen Gallagher - 1.5.1-67Stephen Gallagher - 1.5.1-66Stephen Gallagher - 1.5.1-65Stephen Gallagher - 1.5.1-64Stephen Gallagher - 1.5.1-63Stephen Gallagher - 1.5.1-62Stephen Gallagher - 1.5.1-61Stephen Gallagher - 1.5.1-60Stephen Gallagher - 1.5.1-59Stephen Gallagher - 1.5.1-58Stephen Gallagher - 1.5.1-57Stephen Gallagher - 1.5.1-56Stephen Gallagher - 1.5.1-55Stephen Gallagher - 1.5.1-53Stephen Gallagher - 1.5.1-52Stephen Gallagher - 1.5.1-51Stephen Gallagher - 1.5.1-50Stephen Gallagher - 1.5.1-49Stephen Gallagher - 1.5.1-48Stephen Gallagher - 1.5.1-47Stephen Gallagher - 1.5.1-46Stephen Gallagher - 1.5.1-45Stephen Gallagher - 1.5.1-44Stephen Gallagher - 1.5.1-43Stephen Gallagher - 1.5.1-42Stephen Gallagher - 1.5.1-41Stephen Gallagher - 1.5.1-40Stephen Gallagher - 1.5.1-39Stephen Gallagher - 1.5.1-38Stephen Gallagher - 1.5.1-37Stephen Gallagher - 1.5.1-36Stephen Gallagher - 1.5.1-35Stephen Gallagher - 1.5.1-34Stephen Gallagher - 1.5.1-33Stephen Gallagher - 1.5.1-32Stephen Gallagher - 1.5.1-31Stephen Gallagher - 1.5.1-30Stephen Gallagher - 1.5.1-29Stephen Gallagher - 1.5.1-28Stephen Gallagher - 1.5.1-27Stephen Gallagher - 1.5.1-26Stephen Gallagher - 1.5.1-25Stephen Gallagher - 1.5.1-24Stephen Gallagher - 1.5.1-23Stephen Gallagher - 1.5.1-21Stephen Gallagher - 1.5.1-20Stephen Gallagher - 1.5.1-17Stephen Gallagher - 1.5.1-16Stephen Gallagher - 1.5.1-15Stephen Gallagher - 1.5.1-14Stephen Gallagher - 1.5.1-13Stephen Gallagher - 1.5.1-12Stephen Gallagher - 1.5.1-11Stephen Gallagher - 1.5.1-10Stephen Gallagher - 1.5.1-9Stephen Gallagher - 1.5.1-8Stephen Gallagher - 1.5.1-7Stephen Gallagher - 1.5.1-6Stephen Gallagher - 1.5.1-5Stephen Gallagher - 1.5.1-4Stephen Gallagher - 1.5.1-3Stephen Gallagher - 1.5.1-2Stephen Gallagher - 1.5.1-1Stephen Gallagher - 1.5.0-2Stephen Gallagher - 1.5.0-1Stephen Gallagher - 1.2.1-28.4Stephen Gallagher - 1.2.1-36Stephen Gallagher - 1.2.1-35Stephen Gallagher - 1.2.1-28.3Stephen Gallagher - 1.2.1-34Stephen Gallagher - 1.2.1-28.2Stephen Gallagher - 1.2.1-33Stephen Gallagher - 1.2.1-28.1Stephen Gallagher - 1.2.1-32Stephen Gallagher - 1.2.1-29Stephen Gallagher - 1.2.1-28Stephen Gallagher - 1.2.1-27Stephen Gallagher - 1.2.1-26Stephen Gallagher - 1.2.1-23Stephen Gallagher - 1.2.1-21Stephen Gallagher - 1.2.1-20Stephen Gallagher - 1.2.1-19Stephen Gallagher - 1.2.1-15Stephen Gallagher - 1.2.0-14Stephen Gallagher - 1.2.0-13Stephen Gallagher - 1.2.0-12Stephen Gallagher - 1.1.92-11.1Stephen Gallagher - 1.1.92-11Stephen Gallagher - 1.1.91-10Simo Sorce - 1.1.1-3Stephen Gallagher - 1.1.1-1Stephen Gallagher - 1.1.0-2Stephen Gallagher - 1.1.0-1.pre20100317git0ea7f19Stephen Gallagehr - 1.0.5-2Stephen Gallagher - 1.0.5-1Stephen Gallagher - 1.0.4-1Stephen Gallagher - 1.0.3-1Stephen Gallagher - 1.0.2-1Stephen Gallagher - 1.0.1-1Stephen Gallagher - 1.0.0-2Stephen Gallagher - 1.0.0-1Stephen Gallagher - 0.99.1-1Stephen Gallagher - 0.99.0-1Stephen Gallagher - 0.7.1-1Stephen Gallagher - 0.7.0-2Stephen Gallagher - 0.7.0-1Stephen Gallagher - 0.6.1-2Stephen Gallagher - 0.6.1-1Stephen Gallagher - 0.6.0-1Sumit Bose - 0.6.0-0Simo Sorce - 0.5.0-0Jakub Hrozek - 0.4.1-4Fedora Release Engineering - 0.4.1-3Simo Sorce - 0.4.1-2Simo Sorce - 0.4.1-1Simo Sorce - 0.4.1-0Simo Sorce - 0.3.2-2Jakub Hrozek - 0.3.2-1Simo Sorce - 0.3.1-2Simo Sorce - 0.3.1-1Simo Sorce - 0.3.0-2Simo Sorce - 0.3.0-1Simo Sorce - 0.2.1-1Simo Sorce - 0.2.0-1Jakub Hrozek - 0.1.0-5.20090309git691c9b3Jakub Hrozek - 0.1.0-4Sumit Bose - 0.1.0-3Jakub Hrozek - 0.1.0-2Stephen Gallagher - 0.1.0-1- Related: rhbz#1442703 - Smart Cards: Certificate in the ID View - Related: rhbz# 1401546 - Please back-port fast failover from sssd 1.14 on RHEL 7 into sssd 1.13 on RHEL 6- Resolves: rhbz#1326007 - Memory cache corruption when rsync and/or tar to copy owner and group info from LDAP - Resolves: rhbz#1442703 - Smart Cards: Certificate in the ID View - Resolves: rhbz#1507435 - CVE-2017-12173 sssd: unsanitized input when searching in local cache database [rhel-6.10] - Resolves: rhbz#1487040 - sssd does not evaluate AD UPN suffixes which results in failed user logins- Resolves: rhbz#1421057 - pam_sss crashes in do_pam_conversation if no conversation function is provided by the client app - Resolves: rhbz#1487040 - sssd does not evaluate AD UPN suffixes which results ini failed user logins - Resolves: rhbz#1487944 - ABRT crash - /usr/libexec/sssd/sssd_nss - Resolves: rhbz#1489485 - sssd is not pulling groups in a trusted domain, with the Global scope- Resolves: rhbz#1438360 - The originalMemberOf attribute disappears from the cache, causing intermittent HBAC issues- Resolves: rhbz#1404697 - SSSD does not skip GPO if no gpcFunctionalityVersion present - Resolves: rhbz#1374813 - SSSD fails to process GPO from Active Directory- Resolves: rhbz#1415785 - ldap_child does not remove temporary files when it's killed with SIGTERM- Apply several more smartcard-related patches. - Related: rhbz#1300421 - Screen locks and smart card is removed - must show a message to insert the correct smartcard- Resolves: rhbz#1400643 - sssd prevents sudo from getting data from LDAP- Resolves: rhbz#1393592 - SSH-CERT: always initialize cert_verify_opts- Revert the ding-libs requirement - Related: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Related: rhbz#1369921 - Members of nested netgroups configured in IdM cannot be seen by getent on clients- Require the matching version of ding-libs - Related: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Fix a coverity warning - Related: rhbz#1382395 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1382395 - sudo: ignore case on case insensitive domains- Resolves: rhbz#1369921 - Members of nested netgroups configured in IdM cannot be seen by getent on clients- Resolves: rhbz#1324428 - [RFE] Discover forest's root SID even if subdomains_provider = none- Resolves: rhbz#1367802 - using overides causes segfault in libldb- Resolves: rhbz#1329378 - pam_sss set KRB5CCNAME with sudo logins- Resolves: rhbz#1382603 - autofs map resolution doesn't work offline- Resolves: rhbz#1339986 - [sssd-ldap] man page needs attention- Resolves: rhbz#1321884 - IPA sudo: support the externalUser attribute- Resolves: rhbz#1299994 - ssh client checks only the first certificate on a smartcard when the card has multiple certs - Resolves: rhbz#1300421 - Screen locks and smart card is removed - must show a message to insert the correct smartcard - Resolves: rhbz#1372681 - ssh with Smartcards - skip invalid certificates- Resolves: rhbz#1329648 - Protocol error with IPA on RHEL-6 - Resolves: rhbz#1329647 - IPA view: view name not stored properly with default FreeIPA installation- Resolves: rhbz#1339986 - [sssd-ldap] man page needs attention- Resolves: rhbz#1327272 - local overrides: issues with sub-domain users and mixed case names- Resolves: rhbz#1293168 - Inconsistent user synching between IPA and AD- Resolves: rhbz#1374813 - SSSD fails to process GPO from Active Directory.- Resolves: rhbz#1377782 - sssd is looking at a server in the GC of a subdomain, not the root domain.- Resolves: rhbz#1365218 - SSSD does not fail over to next GC- Resolves: rhbz#1367435 - Intermittent sssd auth failures- Resolves: rhbz#1369079 - sssd runs out of available child slots and starts queuing requests in proxy mode- Resolves: rhbz#1338619 - segmentation fault in sssd after upgrade to sssd-1.13.3-22.el6.x86_64 when upgrading cache- Resolves: rhbz#1324107 - GPO: Access denied after blocking connection to AD.- Resolves: rhbz#1293168 - Inconsistent user synching between IPA and AD- Resolves: rhbz#1340927 - sssd-common requires libnfsidmap- Resolves: rhbz#1340176 - The AD keytab renewal task leaks a file descriptor- Resolves: rhbz#1335400 - In IPA-AD trust environment access is granted to AD user even if the user is disabled on AD.- Resolves: rhbz#1336453 - sssd_be doesn't terminate forked child process if adcli is not installed- Resolves: rhbz#1312062 - sssd does not pass LDAP rules to sudo- Resolves: rhbz#1313940 - SSSD PAM module does not support multiple password prompts (e.g. Password + Token) with sudo- Actually apply patches from previous build - Resolves: rhbz#1313940 - sudorule not working with ipa sudo_provider- Resolves: rhbz#1313940 - sudorule not working with ipa sudo_provider- Resolves: rhbz#1209600 - Getting ERROR (getpwnam() failed): Broken pipe with 1.11.6- Backport of a more minimal dependency patch to avoid changes to AD provider behaviour - Related: rhbz#1264705 - Allow SSSD to notify user of denial due to AD account lockout- Resolves: rhbz#1308939 - After removing certificate from user in IPA and even after sss_cache, FindByCertificate still finds the user- Require a newer selinux-policy to avoid issues when prompting for SC PIN - Related: rhbz#1299066 - smartcard login does not prompt for pin when ocsp checking is enabled (default config)- Resolves: rhbz#1264705 - Allow SSSD to notify user of denial due to AD account lockout- Resolves: rhbz#1259687 - sssd_nss memory usage keeps growing on sssd-1.12.4-47.el6.x86_64 (RHEL6.7) when trying to retrieve non-existing netgroups- Update sssd-ldap man page for the recent ID mapping changes - Related: rhbz#1268902 - SSSD doesn't set the ID mapping range automatically- Resolves: rhbz#1295883 - refresh_expired_interval stops sss_cache from working- Resolves: rhbz#1268902 - SSSD doesn't set the ID mapping range automatically- Resolves: rhbz#1298253 - Screen lock prompts for smartcard user password and not smartcard pin when logged in using smartcard pin- Resolves: rhbz#1292458 - sssd_be AD segfaults on missing A record- Resolves: rhbz#1262981 - sssd dereference processing failed : Input/output error- Resolves: rhbz#1290761 - [RFE] Support Automatic Renewing of Kerberos Host Keytabs- Resolves: rhbz#1244957 - [RFE] SUDO: Support the IPA schema- Resolves: rhbz#1298634 - Cannot retrieve users after upgrade from 1.12 to 1.13- Resolves: rhbz#1287807 - SRV lookup for KDC servers doesn't work- Resolves: rhbz#1273802 - ad_site parameter does not work- Fix memory leak in the NFS plugin - Related: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - Resolves: rhbz#1296620 - Properly remove OriginalMemberOf attribute in SSSD cache if user has no secondary groups anymore - Resolves: rhbz#1283898 - MAN: Clarify that subdomains always use service discovery- Rebase to 1.13.3 - Remove setuid bit from proxy_child, RHEL-6 doesn't support running SSSD as a non-privileged user - Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8- Don't own files as the SSSD user - Resolves: rhbz#1289482 - warning: user sssd does not exist - using root- Resolves: rhbz#1279971 - groups get deleted from the cache- The p11_child doesn't have to run privileged anymore, remove the setuid bit - Related: rhbz#1270027 - [RFE] Support for smart cards- Resolves: rhbz#1266108 - Check next certificate on smart card if first is not valid - Also enable OCSP checks- Resolves: rhbz#1285852 - sssd: [sysdb_add_user] (0x0400): Error: 17 (File exists)- Silence compilation warnings and Coverity issues - Related: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8- Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - Squash in packaging review changes by lslebodn@redhat.com- Resolves: rhbz#1269820 - Rebase SSSD to 1.13.x in RHEL-6.8 - The rebase also resolves the following bugzillas: - Resolves: rhbz#1270029 - [RFE] Add a way to lookup users based on CAC identity certificates - Resolves: rhbz#1270027 - [RFE] Support for smart cards - Resolves: rhbz#1269422 - [FEAT] UID and GID mapping on individual clients - Resolves: rhbz#1269421 - [RFE] The fast memory cache should cache initgroups - Resolves: rhbz#1265429 - If the site discovery fails, ad-site option is not taken into account. - Resolves: rhbz#1254193 - Fix for cyclic dependencies between sssd-{krb5,}-common - Resolves: rhbz#1247997 - [IPA/IdM] sudoOrder not honored as expected - Resolves: rhbz#1237142 - [RFE] authenticate against cache in SSSD - Resolves: rhbz#1232632 - Kerberos-based providers other than krb5 do not queue requests - Resolves: rhbz#1227804 - Group members are not turned into ghost entries when the user is purged from the SSSD cache - Resolves: rhbz#1227685 - sssd with ldap backend throws error domain log - Resolves: rhbz#1221365 - [RFE] Support GPOs from different domain controllers - Resolves: rhbz#1215195 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1196204 - sssd cache holding gid values for nss, but not the alpha group name representation - Resolves: rhbz#1194039 - [RFE] User's home directories are not taken from AD when there is an IPA trust with AD- Resolves: rhbz#1266404 - Memory leak / possible DoS with krb auth.- Resolves: rhbz#1264524 - SSSD POSIX attribute check is too strict- Resolves: rhbz#1255285 - cleanup_groups should sanitize dn of groups- Resolves: rhbz#1251349 - sysdb sudo search doesn't escape special characters- Resolves: rhbz#1232738 - Cache is not updated after user is deleted from ldap server- Resolves: rhbz#1227860 - Provide a way to disable the cleanup task - Resolves: rhbz#1227863 - ignore_group_members doesn't work for subdomains- Resolves: rhbz#1226834 - id lookup for non-root domain users doesn't return all groups on first attempt- Resolves: rhbz#1225614 - IPA enumeration provider crashes- Resolves: rhbz#1212610 - sssd ad groups work intermittently- Resolves: rhbz#1215765 - sssd nss responder gets wrong number of secondary groups- Resolves: rhbz#1221358 - SSSD doesn't work with ID mapping and disabled subdomains- Resolves: rhbz#1219844 - Unable to resolve group memberships for AD users when using sssd-1.12.2-58.el7_1.6.x86_64 client in combination with ipa-server-3.0.0-42.el6.x86_64 with AD Trust- Resolves: rhbz#1216094 - /usr/libexec/sssd/selinux_child crashes and gets avc denial when ssh- Include several upstream fixes related to ID views - Resolves: rhbz#1215195 - Override for IPA users with login does not list user all groups - Resolves: rhbz#1213947 - Group resolution is inconsistent with group overrides - Resolves: rhbz#1213822 - Overrides with --login work in second attempt- Resolves: rhbz#1217328 - autofs provider fails when default_domain_suffix and use_fully_qualified_names set- Resolves: rhbz#1212387 - sssd_be segfault id_provider = ad src/providers/ad/ad_gpo.c:843- Resolves: rhbz#1213940 - Overridde with --login fails trusted adusers group membership resolution- Resolves: rhbz#1170910 - SSSD should not fail authentication when only allow rules are used- Resolves: rhbz#1213716 - idoverridegroup for ipa group with --group-name does not work - Resolves: rhbz#1213822 - Overrides with --login work in second attempt- Resolves: rhbz#1212017 - Sudo responder does not respect filter_users and filter_groups- Resolves: rhbz#1203642 - GPO access control looks for computer object in user's domain only- Related: rhbz#1211728 - Only set the selinux context if the context differs from the local one- Package the localauth plugin - Related: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Resolves: rhbz#1207720 - id lookup resolves "Domain Local" group and errors appear in domain log- BuildRequire the proper libkrb5 version for correct localauth plugin build - Related: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Resolves: rhbz#1194367 - sssd_be dumping core- Resolves: rhbz#1206121 - ldap_access_order=ppolicy: Explicitly mention in manpage that unsupported time specification will lead to sssd denying access- Resolves: rhbz#1205382 - Properly handle AD's binary objectGUID- Resolves: rhbz#1205716 - Installing sssd-common-1.12.4-18.el6 might install with wrong user account (root)- Fix a typo in DEBUG message - Related: rhbz#1173198 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires- Handle TTL=0 in SRV queries correctly - Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query- Cherry-pick unit test changes from upstream to allow cherry-picking sssd-1-12 patches - Remove unused LDAP provider code to avoid static analyser warnings - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1206092 - sssd crashes intermittently in GPO code- Resolves: rhbz#1202728 - sssd-ad requires samba3, but ipa-server-trust-ad requires samba4- Resolves: rhbz#1203630 - SSSD doesn't own the GPO cache directory- Fix warning in SELinux code - Handle setups with empty default and no SELinux maps - Related: rhbz#1194302 - With empty ipaselinuxusermapdefault security context on client is staff_u - Resolves: rhbz#1202305 - sssd_be segfault on IPA(when auth with AD trusted domain) client at src/providers/ipa/ipa_s2n_exop.c:1605 - Resolves: rhbz#1201847 - SSSD downloads too much information when fetching information about groups- Fix PAM responder initgroups cache for subdomain users - Log extop failures better - Related: rhbz#1168344 - [RFE] ID Views: Support migration from the sync solution to the trust solution- Fix internal error codes broken when fixing rhbz#1036745 - Related: rhbz#1036745 - [RFE] Allow SSSD to issue shadow expiration warning even if alternate authentication method is used- Resolves: rhbz#1200093 - sssd_nss segfaults if initgroups request is by UPN and doesn't find anything- Fix Coverity warning in ldap_child - Add better debugging - Related: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1098147 - [RFE] Implement background refresh for users, groups or other cache objects- Resolves: rhbz#1173198 - [RFE] Have OpenLDAP lock out ssh keys when account naturally expires- Initialize a pointer in ldap_child to NULL - Resolves: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Relax the ldb requirement - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1194302 - With empty ipaselinuxusermapdefault security context on client is staff_u- Resolves: rhbz#1198478 - ccname_file_dummy is not unlinked on error- Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query- Resolves: rhbz#1171378 - Read and use the TTL value when resolving a SRV query - Rebuild against latest krb5, add a versioned BuildRequires - Resolves: rhbz#1168357 - [RFE] Implement localauth plugin for MIT krb5 1.12- Related: rhbz#1036745 - [RFE] Allow SSSD to issue shadow expiration warning even if alternate authentication method is used- Do not mark the selinux_child helper as setuid, we don't support rootless SSSD in 6.7 - Related: rhbz#1168347 - Rebase sssd to 1.12.x- Resolves: rhbz#1168347 - Rebase sssd to 1.12.x - The rebase resolves the following RHEL bugzillas - Resolves: rhbz#1172865 - sssd.conf(5) man page gives bad advice about domains parameter - Resolves: rhbz#1172494 - PAC: krb5_pac_verify failures should not be fatal (backport fix from upstream) - Resolves: rhbz#1171782 - [RFE]: SSSD should preserve case for user uid field - Resolves: rhbz#1170910 - SSSD should not fail authentication when only allow rules are used - Resolves: rhbz#1168377 - [RFE] User's home directories and shells are not taken from AD when there is an IPA trust with AD - Resolves: rhbz#1168363 - [RFE] Add domains= option to pam_sss - Resolves: rhbz#1168344 - [RFE] ID Views: Support migration from the sync solution to the trust solution - Resolves: rhbz#1161564 - [RFE]ad provider dns_discovery_domain option: kerberos discovery is not using this option - Resolves: rhbz#1148582 - inconsistent group information when multiple ad domain sections are configured in sssd - Resolves: rhbz#1140909 - sssd.conf man page missing subdomains_provider ad support - Resolves: rhbz#1139878 - SSSD connection terminated after failing anonymous bind to IBM Tivoli Directory Server - Resolves: rhbz#1135838 - Man sssd-ldap shows parameter ldap_purge_cache_timeout with "Default: 10800 (12 hours)" - Resolves: rhbz#1135432 - Dereference code errors out when dereferencing entries protected by ACIs - Resolves: rhbz#1134942 - sssd does not recognize Windows server 2012 R2's LDAP as AD - Resolves: rhbz#1123291 - automount segfaults in sss_nss_check_header - Resolves: rhbz#1088402 - [RFE] Allow login through SSSD using multiple attributes- Resolves: rhbz#1154042 - RHEL6.6 sssd (1.11) doesn't return all group memberships against an IPA server- Resolves: rhbz#1160713 - TokenGroups for LDAP provider breaks in corner cases- Resolves: rhbz#1141814 - Password expiration policies are not being enforced by SSSD- Resolves: rhbz#1139044 - RHEL6.6 ipa user private group not found- Resolves: rhbz#1103487 - CVE-2014-0249 - sssd: incorrect expansion of group membership when encountering a non-POSIX group- Resolves: rhbz#1125187 - simple_allow_groups does not lookup groups from other AD domains- Resolves: rhbz#1127270 - sssd connect to ipa-server is long- Resolves: rhbz#1130017 - Saving group membership fails if provider is AD, POSIX attributes are used and primary group contains the user as a member- Resolves: rhbz#1111528 - Expired shadow policy user(shadowLastChange=0) is not prompted for password change- Resolves: rhbz#1132361 - use-after-free in dyndns code- Resolves: rhbz#1099290: RFE: Be able to configure sssd to honor openldap account lock to restrict access via ssh key- Use the correct sudo iterator - Related: rhbz#1118336 - sudo: invalid sudoHost filter with asterisk- Add notes about offline mode to sssd.conf - Related: rhbz#1110226 - Requests queued during transition from offline to online mode- Resolves: rhbz#1127278 - Auth fails when space in username is replaced with character set by override_default_whitespace- Resolves: rhbz#1127757 - sssd can't retrieve sudo rules when using the "default_domain_suffix" option- Resolves: rhbz#1127265 - Problems with tokengroups and ldap_group_search_base- Resolves: rhbz#1126636 - RHEL6.6 sssd not running after upgrade- Resolves: rhbz#1128612 - IFP: FQDN lookups are broken- Resolves: rhbz#1118336 - sudo: invalid sudoHost filter with asterisk- Resolves: rhbz#1110226 - Requests queued during transition from offline to online mode- Resolves: rhbz#1122873 - Failover does not always happen from SRV to hostname resolution(via /etc/hosts) - Remove spurious systemctl call on %postun- Resolves: rhbz#1111317 - [RFE] Add option for sssd to replace space with specified character in LDAP group- Resolves: rhbz#1109188 - dereferencing control failure against openldap server- Resolves: rhbz#1084532 - sssd_sudo process segfaults- Resolves: rhbz#1122158 - ad: group membership is empty when id mapping is off and tokengroups are enabled- Resolves: rhbz#1118541 - Floating point exception using ldap- Resolves: rhbz#1042922 - [RFE] Add fallback to sudoRunAs when sudoRunAsUser is not defined and no ldap_sudorule_runasuser mapping has been defined in SSSD- Resolves: rhbz#1120508 - tokengroups do not work with id_provider=ldap- Fix potential NULL dereference in IFP code - Related: rhbz#1110369 - sssd is started before messagebus, making sssd-ifp fail- BuildRequire the latest libini_config - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Resolves: rhbz#1110369 - sssd is started before messagebus, making sssd-ifp fail- Resolves: rhbz#1104145 - public key validator is too strict and does not allow newlines anywhere in the public key string, not even at the end- Rebase to 1.11.6 - Resolves: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Rebuild against new ding-libs - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Backport the InfoPipe patches needed for Sat6 integration - Related: #1051164 - Rebase SSSD to 1.11+ in RHEL6- Resolves: #1085412 - SSSD Crashes when storage experiences high latency- Resolves: #1051164 - Rebase SSSD to 1.11+ in RHEL6Resolves: #1036168 - sssd can't retrieve auto.master when using the "default_domain_suffix"- Resolves: #1065534 - SSSD pam module accepts usernames with leading spaces- Resolves: #1038098 - sssd_nss grows memory footprint when netgroups are requested- Allow combination of proxy id backend and LDAP auth backend - Resolves: #1025813 - SSSD: Allow for custom attributes in RDN when using id_provider = proxy- Inherit UID limits for subdomains - Resolves: #1020905 - Creating system accounts on a IdM client takes up to 10 minutes when AD trust is configured in the IdM.- Do not crash when LDAP disconnects while a search is still in progress - Resolves: #1019979 - sssd_be segfault when authenticating against active directory- More upstream fixes to prevent memcache crashes - Related: #997406 - sssd_nss core dumps under load- Resolves: #1002929 - sssd_be segfaults if IPA dynamic DNS update times out- Make IPA SELinux provider aware of subdomain users - A better version of already committed patch - Resolves: #954342 - In IPA AD trust setup, the sssd logs throws 'sysdb_search_user_by_name failed' error when AD user tries to login via ipa client.- Resolves: #997406 - sssd_nss core dumps under load - Resolves: #984814 - sssd_nss terminated with segmentation fault- Resolves: #1002161 - large number of sudo rules results in error - Unable to create response: Invalid argument- Silence restorecon on clean install - Resolves: #987456 - RHEL6 sssd upgrade restorecon workaround for /var/lib/sss/mc context- Make IPA SELinux provider aware of subdomain users - Resolves: #954342 - In IPA AD trust setup, the sssd logs throws 'sysdb_search_user_by_name failed' error when AD user tries to login via ipa client.- Print password complexity hint when password change fails with constraint violation - Related: #983028 - passwd returns "Authentication token manipulation error" when entering wrong current password- Resolves: #983028 - passwd returns "Authentication token manipulation error" when entering wrong current password- Resolves: #948830 - sssd do too many disk writes causing delay in "getent netgroup allmachines-netgroup" nested netgroups.- Resolves: #984814 - sssd_nss terminated with segmentation fault- Resolves: #966757 - SSSD failover doesn't work if the first DNS server in resolv.conf is unavailable- Resolves: #963235 - sssd_be crashing with nested ldap groups- Apply a forgotten dependency for patch #254 - Related: #916997 - getgrnam / getgrgid for large user groups is too slow due to range retrieval functionality - Add two fixes for better handling of faulty SRV processing - Related: #954275 - sssd fails connect to IPA server during boot when spanning tree is enabled in network router. - Remove enumerate=true from example in man page - Related: #988381 - clarify the disadvantages of enumeration in sssd.conf- Resolves: #914433 - sssd pam write_selinux_login_file creating the temp file for SELinux data failed- Resolves: #916997 - getgrnam / getgrgid for large user groups is too slow due to range retrieval functionality- Resolves: #918394 - sssd etas 99% CPU and runs out of file descriptors when clearing cache- Resolves: #924113 - man sssd-sudo has wrong title- Resolves: #924397 - document what does access_provider=ad do- Use permissive control when adding ghost users - Resolves: #928797 - cyclic group memberships may not work depending on order of operations- Set correct state of SRV servers on resolving error - Resolves: #954275 - sssd fails connect to IPA server during boot when spanning tree is enabled in network router.- Resolves: #954323 - SSSD doesn't display warning for last grace login.- Format patch to configure sysv script differently - RHEL-6 patch(1) apparently doesn't like the output of git format-patch -M -C and doesn't properly copy files on renames - Resolves: #971435 - Enhance sssd init script so that it would source a configuration.- Resolves: #973345 - SSSD service randomly dies- Resolves: #971435 - Enhance sssd init script so that it would source a configuration- Resolves: #961356 - SUDO is not working for users from trusted AD domain- Resolves: #970519 - [RFE] Add support for suppressing group members- Resolves: #976273 - [RFE] Add a new override_homedir expansion for the "original value"- Resolves: #978966 - sudoHost mismatch response is incorrect sometimes- Clarify the min_id/max_id limits further - Resolves: #978994 - SSSD filter out ldap user/group if uid/gid is zero- Resolves: #979046 - sssd_be goes to 99% CPU and causes significant login delays when client is under load- Resolves: #986379 - sss_cache -N/-n should invalidate the hash table in sssd_nss- Resolves: #988525 - sssd fails instead of skipping when a sudo ldap filter returns entries with multiple CNs- Mention that enumeration should be discouraged - Resolves: #988381 - clarify the disadvantages of enumeration in sssd.conf- Call restorecon on memcache files to force the right context on upgrades - Resolves: #987456 - RHEL6 sssd upgrade restorecon workaround for /var/lib/sss/mc context- Resolves: #987479 - libsss_sudo should depend on sudo package with sssd support- Resolves: #951086 - sssd_pam segfaults if sssd_be is stuck- Resolves: #967636 - SSSD frequently fails to return automount maps from LDAP- Resolves: #953165 - Enabling enumeration causes sssd_be process to utilize 100% of the CPU- Resolves: #906398 - sssd_be crashes sometimes- Resolves: #950874: Simple access control always denies uppercased users in case insensitive domain- Resolves: #921454: Resolve local group members in LDAP groups- Resolves: rhbz#911299 - sssd: simple access provider flaw prevents intended ACL use when client to an AD provider- Fix pwd_expiration_warning=0 - Resolves: rhbz#911329 - pwd_expiration_warning has wrong default for Kerberos- Resolves: rhbz#911329 - pwd_expiration_warning has wrong default for Kerberos- Resolves: rhbz#872827 - Serious performance regression in sssd- Resolves: rhbz#888614 - Failure in memberof can lead to failed database update- Resolves: rhbz#903078 - TOCTOU race conditions by copying and removing directory trees- Resolves: rhbz#903078 - Out-of-bounds read flaws in autofs and ssh services responders- Resolves: rhbz#902716 - Rule mismatch isn't noticed before smart refresh on ppc64 and s390x- Resolves: rhbz#896476 - SSSD should warn when pam_pwd_expiration_warning value is higher than passwordWarning LDAP attribute.- Resolves: rhbz#902436 - possible segfault when backend callback is removed- Resolves: rhbz#895132 - Modifications using sss_usermod tool are not reflected in memory cache- Resolves: rhbz#894302 - sssd fails to update to changes on autofs maps- Resolves: rhbz894381 - memory cache is not updated after user is deleted from ldb cache- Resolves: rhbz895615 - ipa-client-automount: autofs failed in s390x and ppc64 platform- Resolves: rhbz#894997 - sssd_be crashes looking up members with groups outside the nesting limit- Resolves: rhbz#895132 - Modifications using sss_usermod tool are not reflected in memory cache- Resolves: rhbz#894428 - wrong filter for autofs maps in sss_cache- Resolves: rhbz#894738 - Failover to ldap_chpass_backup_uri doesn't work- Resolves: rhbz#887961 - AD provider: getgrgid removes nested group memberships- Resolves: rhbz#878583 - IPA Trust does not show secondary groups for AD Users for commands like id and getent- Resolves: rhbz#874579 - sssd caching not working as expected for selinux usermap contexts- Resolves: rhbz#892197 - Incorrect principal searched for in keytab- Resolves: rhbz#891356 - Smart refresh doesn't notice "defaults" addition with OpenLDAP- Resolves: rhbz#878419 - sss_userdel doesn't remove entries from in-memory cache- Resolves: rhbz#886848 - user id lookup fails for case sensitive users using proxy provider- Resolves: rhbz#890520 - Failover to krb5_backup_kpasswd doesn't work- Resolves: rhbz#874618 - sss_cache: fqdn not accepted- Resolves: rhbz#889182 - crash in memory cache- Resolves: rhbz#889168 - krb5 ticket renewal does not read the renewable tickets from cache- Resolves: rhbz#886091 - Disallow root SSH public key authentication - Add default section to switch statement (Related: rhbz#884666)- Resolves: rhbz#886038 - sssd components seem to mishandle sighup- Resolves: rhbz#888800 - Memory leak in new memcache initgr cleanup function- Resolves: rhbz#888614 - Failure in memberof can lead to failed database update- Resolves: rhbz#885078 - sssd_nss crashes during enumeration if the enumeration is taking too long- Related: rhbz#875851 - sysdb upgrade failed converting db to 0.11 - Include more debugging during the sysdb upgrade- Resolves: rhbz#877972 - ldap_sasl_authid no longer accepts full principal- Resolves: rhbz#870045 - always reread the master map from LDAP - Resolves: rhbz#876531 - sss_cache does not work for automount maps- Resolves: rhbz#884666 - sudo: if first full refresh fails, schedule another first full refresh- Resolves: rhbz#880956 - Primary server status is not always reset after failover to backup server happened - Silence a compilation warning in the memberof plugin (Related: rhbz#877974) - Do not steal resolv result on error (Related: rhbz#882076)- Resolves: rhbz#882923 - Negative cache timeout is not working for proxy provider- Resolves: rhbz#884600 - ldap_chpass_uri failover fails on using same hostname- Resolves: rhbz#858345 - pam_sss(crond:account): Request to sssd failed. Timer expired- Resolves: rhbz#878419 - sss_userdel doesn't remove entries from in-memory cache- Resolves: rhbz#880176 - memberUid required for primary groups to match sudo rule- Resolves: rhbz#885105 - sudo denies access with disabled ldap_sudo_use_host_filter- Resolves: rhbz#883408 - Option ldap_sudo_include_regexp named incorrectly- Resolves: rhbz#880546 - krb5_kpasswd failover doesn't work - Fix the error handler in sss_mc_create_file (Related: #789507)- Resolves: rhbz#882221 - Offline sudo denies access with expired entry_cache_timeout - Fix several bugs found by Coverity and clang: - Check the return value of diff_gid_lists (Related: #869071) - Move misplaced sysdb assignment (Related: #827606) - Remove dead assignment (Related: #827606) - Fix copy-n-paste error in the memberof plugin (Related: #877974)- Resolves: rhbz#882923 - Negative cache timeout is not working for proxy provider - Link sss_ssh_authorizedkeys and sss_ssh_knowhostsproxy with the client libraries (Related: #870060) - Move sss_ssh_knownhosts documentation to the correct section (Related: #870060)- Resolves: rhbz#884480 - user is not removed from group membership during initgroups - Fix incorrect synchronization in mmap cache (Related: #789507)- Resolves: rhbz#883336 - sssd crashes during start if id_provider is not mentioned- Resolves: rhbz#882290 - arithmetic bug in the SSSD causes netgroup midpoint refresh to be always set to 10 seconds- Resolves: rhbz#877974 - updating top-level group does not reflect ghost members correctly - Resolves: rhbz#880159 - delete operation is not implemented for ghost users- Resolves: rhbz#881773 - mmap cache needs update after db changes- Resolves: rhbz#875677 - password expiry warning message doesn't appear during auth - Fix potential NULL dereference when skipping built-in AD groups (Related: rhbz#874616) - Add missing parameter to DEBUG message (Related: rhbz#829742)- Resolves: rhbz#882076 - SSSD crashes when c-ares returns success but an empty hostent during the DNS update - Do not version libsss_sudo, it's not supposed to be linked against, but dlopened (Related: rhbz#761573)- Resolves: rhbz#880140 - sssd hangs at startup with broken configurations- Resolves: rhbz#878420 - SIGSEGV in IPA provider when ldap_sasl_authid is not set- Resolves: rhbz#874616 - Silence the DEBUG messages when ID mapping code skips a built-in group- Resolves: rhbz#824244 - sssd does not warn into sssd.log for broken configurations- Resolves: rhbz#874673 - user id lookup fails using proxy provider - Fix a possibly uninitialized variable in the LDAP provider - Related: rhbz#877130- Resolves: rhbz#878262 - ipa password auth failing for user principal name when shorter than IPA Realm name - Resolves: rhbz#871843 - Nested groups are not retrieved appropriately from cache- Resolves: rhbz#870238 - IPA client cannot change AD Trusted User password- Resolves: rhbz#877972 - ldap_sasl_authid no longer accepts full principal- Resolves: rhbz#861075 - SSSD_NSS failure to gracefully restart after sbus failure- Resolves: rhbz#877354 - ldap_connection_expire_timeout doesn't expire ldap connections- Related: rhbz#877126 - Bump the release tag- Resolves: rhbz#877126 - subdomains code does not save the proper user/group name- Resolves: rhbz#877130 - LDAP provider fails to save empty groups - Related: rhbz#869466 - check the return value of waitpid()- Resolves: rhbz#870039 - sss_cache says 'Wrong DB version'- Resolves: rhbz#875740 - "defaults" entry ignored- Resolves: rhbz#875738 - offline authentication failure always returns System Error- Resolves: rhbz#875851 - sysdb upgrade failed converting db to 0.11- Resolves: rhbz#870278 - ipa client setup should configure host properly in a trust is in place- Resolves: rhbz#871160 - sudo failing for ad trusted user in IPA environment- Resolves: rhbz#870278 - ipa client setup should configure host properly in a trust is in place- Resolves: rhbz#869678 - sssd not granting access for AD trusted user in HBAC rule- Resolves: rhbz#872180 - subdomains: Invalid sub-domain request type - Related: rhbz#867933 - invalidating the memcache with sss_cache doesn't work if the sssd is not running- Resolves: rhbz#873988 - Man page issue to list 'force_timeout' as an option for the [sssd] section- Resolves: rhbz#873032 - Move sss_cache to the main subpackage- Resolves: rhbz#873032 - Move sss_cache to the main subpackage - Resolves: rhbz#829740 - Init script reports complete before sssd is actually working - Resolves: rhbz#869466 - SSSD starts multiple processes due to syntax error in ldap_uri - Resolves: rhbz#870505 - sss_cache: Multiple domains not handled properly - Resolves: rhbz#867933 - invalidating the memcache with sss_cache doesn't work if the sssd is not running - Resolves: rhbz#872110 - User appears twice on looking up a nested group- Resolves: rhbz#871576 - sssd does not resolve group names from AD - Resolves: rhbz#872324 - pam: fd leak when writing the selinux login file in the pam responder - Resolves: rhbz#871424 - authconfig chokes on sssd.conf with chpass_provider directive- Do not send SIGKILL to service right after sending SIGTERM - Resolves: #771975 - Fix the initial sudo smart refresh - Resolves: #869013 - Implement password authentication for users from trusted domains - Resolves: #869071 - LDAP child crashed with a wrong keytab - Resolves: #869150 - The sssd_nss process grows the memory consumption over time - Resolves: #869443- BuildRequire selinux-policy so that selinux login support is built in - Resolves: #867932- Do not segfault if namingContexts contain no values or multiple values - Resolves: rhbz#866542- Fix the "ca" translation of the sssd-simple manual page - Related: rhbz#827606 - Rebase SSSD to 1.9 in 6.4- New upstream release 1.9.2- Rebase to 1.9.1- Require the latest libldb- Rebase to 1.9.0 - Resolves: rhbz#827606 - Rebase SSSD to 1.9 in 6.4- Rebase to 1.9.0 RC1 - Resolves: rhbz#827606 - Rebase SSSD to 1.9 in 6.4 - Bump the selinux-policy version number to pull in required fixes- Resolves: rhbz#840089 - Update the shadowLastChange attribute with days since the Epoch, not seconds- Fix protocol break for services map - Related: rhbz#825028 - Service lookups by port number doesn't work on s390x/ppc64 arches- Resolves: rhbz#825028 - Service lookups by port number doesn't work on s390x/ppc64 arches- Resolves: rhbz#824616 - sssd_nss crashes when configured with use_fully_qualified_names = true- Resolves: rhbz#824062 - sssd_be crashed with SIGSEGV in _tevent_schedule_immediate()- Resolves: rhbz#822236 - SSSD netgroups do not honor entry_cache_nowait_percentage- Resolves: rhbz#820759 - AVC denial seen on sssd upgrade during ipa-client upgrade - Resolves: rhbz#821044 - sss_groupadd no longer detects duplicate GID numbers- Resolves: rhbz#818642 - Auth fails for user with non-default attribute names - Resolves: rhbz#819063 - sssd fails to provide partial data till paged search returns "Size Limit Exceeded" - Resolves: rhbz#820585 - Group enumeration fails in proxy provider- Resolves: rhbz#816616 - group members are now lowercased in case insensitive domains- Resolves: rhbz#805431 - NFS files/folders are mapped to nobody user if NFS top level directory is chowned by a SSSD user- Resolves: rhbz#805924 - SSSD should attempt to get the RootDSE after binding - Resolves: rhbz#814237 - sdap_check_aliases must not error when detects the same user - Resolves: rhbz#812281 - autofs client: map name length used as key length - Related: rhbz#784870 - SSSD fails during autodetection of search bases for new LDAP features - Related: rhbz#814269 - sssd-1.5.1-66.el6_2.3.x86_64 freezes- Fix typo in patch for SSH umask - Related: rhbz#808107 - Coverity revealed memory management defects- Resolves: rhbz#808458 - Authconfig crashes when sets krb realm - Resolves: rhbz#808597 - sssd_nss crashes on request when no back end is running - Resolves: rhbz#808107 - Coverity revealed memory management defects- Related: rhbz#805452 - Unable to lookup user, group, netgroup aliases with case_sensitive=false- Resolves: rhbz#804057 - Initial service lookups having name with uppercase alphabets doesn't work - Resolves: rhbz#804065 - Service lookup using case-sensitive protocol names doesn't work when case_sensitive=false - Resolves: rhbz#805281 - sssd: Uses the wrong key when there a multiple realms in a single keytab - Resolves: rhbz#805452 - Unable to lookup user, group, netgroup aliases with case_sensitive=false - Resolves: rhbz#805918 - Wrong resolv_status might cause crash when name resolution times out - Resolves: rhbz#805431 - NFS files/folders are mapped to nobody user if NFS top level directory is chowned by a SSSD user- Related: rhbz#802207 - getent netgroup hangs when "use_fully_qualified_names = TRUE" in sssd - Resolves: rhbz#801719 - "Error looking up public keys" while ssh to replica using IP address - Resolves: rhbz#803659 - Service lookup shows case sensitive names twice with case_sensitive=false - Resolves: rhbz#803842 - Unable to bind to LDAP server when minssf set - Resolves: rhbz#805034 - accessing an undefined variable might cause crash - Resolves: rhbz#805108 - sss_ssh_knownhostproxy infinite loop hangs SSH login- Update translations - Resolves: rhbz#802372 - Pick up latest translation files for SSSD - Resolves: rhbz#802207 - getent netgroup hangs when "use_fully_qualified_names = TRUE" in sssd - Related: rhbz#801451 - Logging in with ssh pub key should consult authentication authority policies- Resolves: rhbz#801407 - sssd_nss gets hung processing identical search requests - Resolves: rhbz#801451 - Logging in with ssh pub key should consult authentication authority policies - Resolves: rhbz#795562 - Infinite loop checking Kerberos credentials - Resolves: rhbz#798317 - sssd crashes when ipa_hbac_support_srchost is set to true - Resolves: rhbz#799039 - --debug option for sss_debuglevel doesn't work - Resolves: rhbz#799915 - Unable to lookup netgroups with case_sensitive=false - Resolves: rhbz#799929 - Raise limits for max num of files sssd_nss/sssd_pam can use - Resolves: rhbz#799971 - sssd_be crashes on shutdown - Resolves: rhbz#801533 - sssd_be crashes when resolving non-trivial nested group structure - Resolves: rhbz#801368 - Group lookups doesn't return members with proxy provider configured - Resolves: rhbz#801377 - getent returns non-existing netgroup name, when sssd is configured as proxy provider- Do not auto-upgrade debug levels - Tool still available for manual use - Reverts: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade - Resolves: rhbz#798881 - Install-time warnings - Resolves: rhbz#798774 - IPA provider should assume that ipa_domain is also the dns_discovery_domain - Resolves: rhbz#798655 - Password logins failing due to a process with high UID- Fix explicit requires to use openldap instead of openldap-libs - Related: rhbz#797282 - sssd-1.5.1-66.el6.x86_64 needs openldap >= openldap-2.4.23-20.el6.x86_64- Fix multilib-clean issue due to upgrade script - Remove old copy from the spec file - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Fix typo in the patch - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Use a patch and install the script to python_sitelib - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Fix multilib-clean issue due to upgrade script - Related: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade- Resolves: rhbz#753763 - Provide logging configuration compatibility on SSSD 1.5/1.6 upgrade - Resolves: rhbz#785871 - wrong build dependency on nscd - Resolves: rhbz#785873 - IPA host search base cannot be set - Resolves: rhbz#791208 - Entries lacking a POSIX username value break group lookups - Resolves: rhbz#796307 - Simple Paged Search control needs to be used more sparingly - Resolves: rhbz#797282 - sssd-1.5.1-66.el6.x86_64 needs openldap >= openldap-2.4.23-20.el6.x86_64 - Resolves: rhbz#787035 - ipa - sssd slow response with thousands of user entries - Resolves: rhbz#742509 - [RFE] Add SSSD Tool to purge cache - Resolves: rhbz#772297 - Fails to update if all nisNetgroupTriple or memberNisNetgroup entries are deleted from a netgroup - Resolves: rhbz#783138 - Backend occasionally goes offline under heavy load - Resolves: rhbz#797975 - sssd_be: The requested target is not configured is logged at each login - Resolves: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3- Resolves: rhbz#761570 - [RFE] support looking up autofs maps via SSSD - Resolves: rhbz#788979 - sssd crashes during initgroups against a user belonging to nested rfc2307bis group- Handle filtering python Provides in a safer way - Related: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3- Related: rhbz#735422 - Rebase SSSD to 1.8.0 in RHEL 6.3 - Resolves: rhbz#786553 - sssd on ppc64 doesn't pull cyrus-sasl-gssapi.ppc as a dependancy - Resolves: rhbz#785909 - --debug-timestamps=1 is not passed to providers - Resolves: rhbz#785908 - ldap_*_search_base doesn't fully limit the group and netgroup search base correctly - Resolves: rhbz#785907 - [RFE] Add support to request canonicalization on krb AS requests - Resolves: rhbz#785905 - [RFE] DEBUG timestamps should offer higher precision - Resolves: rhbz#785904 - [RFE] SSSD should have --version option - Resolves: rhbz#785902 - Errors with empty loginShell and proxy provider - Resolves: rhbz#785898 - Enable midway cache refresh by default - Resolves: rhbz#785888 - sssd returns empty netgroup at a second request for a non-existing netgroup - Resolves: rhbz#785884 - Honour TTL when resolving host names - Resolves: rhbz#785883 - check DNS records before updates - Resolves: rhbz#785881 - List the keytab to pick the princiapl to use instead of guessing - Resolves: rhbz#785880 - debug_level in sssd.conf overrides command-line - Resolves: rhbz#785879 - sss_obfuscate/python config parser modifies config file too much - Resolves: rhbz#785877 - on reconnect we need to detect that a ipa/ds server has been reinitialized - Resolves: rhbz#785741 - sssd.api.conf and sssd.api.d should not be in /etc - Resolves: rhbz#773660 - Kerberos errors should go to syslog - Resolves: rhbz#772163 - Iterator loop reuse cases a tight loop in the native IPA netgroups code - Resolves: rhbz#771706 - sssd_be crashes during auth when there exists UTF source host group in an hbacrule - Resolves: rhbz#771702 - sssd_pam crashes during change password operation against a IPA server - Resolves: rhbz#771361 - case_sensitive function not working as intended for ldap - Resolves: rhbz#768935 - Crash when applying settings - Resolves: rhbz#766941 - The full dyndns update message should be logged into debug logs - Resolves: rhbz#766930 - [RFE] Add a new option to override home directory value - Resolves: rhbz#766913 - [RFE] Add option to select validate and FAST keytab principal name - Resolves: rhbz#766907 - Use [...] for IPv6 addresses in kdc info files - Resolves: rhbz#766904 - [RFE] Create a command line tool to change the debug levels on the fly - Resolves: rhbz#766876 - [RFE] Make HBAC srchost processing optional - Resolves: rhbz#766141 - [RFE] SSSD should support FreeIPA's internal netgroup representation - Resolves: rhbz#761582 - [RFE] Add ldap_sasl_minssf option - Resolves: rhbz#759186 - [abrt] sssd-1.6.3-1.fc16: ping_check: Process /usr/sbin/sssd was killed by signal 11 (SIGSEGV) - Resolves: rhbz#755506 - [RFE] Add host-based (pam_host_attr) access control - Resolves: rhbz#753876 - [RFE] Add support for the services map - Resolves: rhbz#746181 - "getgrgid call returned more than one result" after group name change in MSAD - Resolves: rhbz#744197 - [RFE] close LDAP connection to the server when idle for some (configurable) time - Resolves: rhbz#742510 - [RFE] Separate Cache Timeouts for SSSD - Related: rhbz#742509 - [RFE] Add SSSD Tool to purge cache - Resolves: rhbz#742052 - id -G group resolution takes extremely long - Resolves: rhbz#739312 - [RFE] sssd does not set shadowLastChange - Resolves: rhbz#736150 - [RFE] SSSD should support multiple search bases - Resolves: rhbz#735827 - [RFE] Ability to set a domain as case sensitive or insensitive - Resolves: rhbz#735405 - [RFE] Option to disable warnings for unknown users - Resolves: rhbz#728212 - [RFE] sssd does not handle when paging control disabled for openldap - Resolves: rhbz#726467 - SSSD takes 30+ seconds to login - Resolves: rhbz#721289 - Process /usr/libexec/sssd/sssd_be was killed by signal 11 during auth when password for the user is not set- Resolves: rhbz#773655 - Race-condition bug in LDAP auth provider- Resolves: rhbz#753842 - sssd_nss crashes when passed invalid UTF-8 for the username in getpwnam() - Resolves: rhbz#758157 - LDAP failover not working if server refuses connections- Related: rhbz#750359 - Major cached entry performance regression- Resolves: rhbz#750359 - Major cached entry performance regression- Resolves: rhbz#749822 - SSSD may go into infinite loop during RFC2307bis initgroups when groups appear in multiple nesting levels- Resolves: rhbz#749256 - SELinux errors with SSSD Downgrade- Resolves: rhbz#748924 - RHEL6.1/sssd_pam segmentation fault- Resolves: rhbz#748412 - Memory leaks during the initgroups() operation- Related: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#742288 - RFC2307bis initgroups calls are slow - Resolves: rhbz#746654 - SSSD backend gets killed on slow systems - Related: rhbz#743925 - HBAC processing is very slow when dealing with FreeIPA deployments with large numbers of hosts Fixes a crash introduced by the earlier patch. - Related: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names Fixes for internationalization- Related: rhbz#742278 - Rework the example config- Resolves: rhbz#743925 - HBAC processing is very slow when dealing with FreeIPA deployments with large numbers of hosts - Resolves: rhbz#745966 - sssd_pam segfaults on sssd restart - Related: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#742278 - Rework the example config - Resolves: rhbz#746037 - Only access sssd_nss internal hash table if it was initialized - Resolves: rhbz#742526 - SSSD's man pages are missing information - Resolves: rhbz#743841 - SSSD can crash due to dbus server removing a UNIX socket- Resolves: rhbz#738621 - Lookup fails for non-primary usernames with multi-valued uid - Resolves: rhbz#738629 - Group lookups doesn't return it's member for sometime when the member has multi-valued uid - Resolves: rhbz#742295 - Use an explicit base 10 when converting uidNumber to integer - Resolves: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names- Resolves: rhbz#741751 - HBAC rule evaluation does not properly handle host groups - Resolves: rhbz#740501 - SSSD not functional after "self" reboot - Resolves: rhbz#742539 - HBAC: Hostname comparisons should be case-insensitive- Resolves: rhbz#728343 - SSSD taking 5 minutes to log in - Resolves: rhbz#739850 - Coverity defects newly introduced in rhel 6.2- Resolves: rhbz#737157 - "System error" appears in log during change password operation of a user in openldap server with ppolicy enabled - Resolves: rhbz#737172 - "Unknown (private extension) error(21853), (null)" messages are logged during change password operation of a user in openldap server with ppolicy enabled- Resolves: rhbz#736314 - sssd crashes during auth while there exists multiple external hosts along with managed host - Resolves: rhbz#732974 - [RFE] Have SSSD cache properly with krb5_validate = True and SElinux enabled- Resolves: rhbz#732010 - LDAP+GSSAPI needs explicit Kerberos realm - Resolves: rhbz#733382 - SSSD should pick a user/group name when there are multi-valued names - Resolves: rhbz#733409 - Improve password policy error message - Resolves: rhbz#733663 - Authentication fails when there exists an empty hbacsvcgroup - Resolves: rhbz#732935 - Add LDAP provider option to set LDAP_OPT_X_SASL_NOCANON - Resolves: rhbz#734101 - sssd blocks login of ipa-users- Related: rhbz#728353 - Resolve RPMDiff errors in SSSD- Resolves: rhbz#728961 - Provide a mechanism for vetoing the use of certain shells- Related: rhbz#728267 - When non-posix groups are skipped, initgroups returns random GID- Related: rhbz#726466 - HBAC rule evaluation does not support extended UTF-8 languages - Related: rhbz#718250 - Remove DENY rules from the HBAC access provider - Fixes an issue on big endian platforms- Resolves: rhbz#700828 - Process /usr/libexec/sssd/sssd_be was killed by signal 11 (SIGSEGV) when ldap_uri is misconfigured - Resolves: rhbz#726438 - sssd doesn't honor ldap supportedControls - Resolves: rhbz#726466 - HBAC rule evaluation does not support extended UTF-8 languages - Resolves: rhbz#718250 - Remove DENY rules from the HBAC access provider - Resolves: rhbz#728267 - When non-posix groups are skipped, initgroups returns random GID - Resolves: rhbz#726475 - sssd_pam leaks file descriptors - Resolves: rhbz#725868 - Explicitly ignore groups with gidNumber = 0- Related: rhbz#721052 - sssd does not handle kerberos server IP change - Use ares_search instead of ares_query to honor - search entries in /etc/resolv.conf- Resolves: rhbz#711416 - During the change password operation the ccache is - not replaced by a new one if the old one isn't - active anymore - Resolves: rhbz#715609 - Certificate validation fails with message - "Connection error: TLS: hostname does not match CN - in peer certificate" - Resolves: rhbz#719089 - IPA dynamic DNS update mangles AAAA records - Resolves: rhbz#721052 - sssd does not handle kerberos server IP change - Honor TTL values when resolving hostnames- Resolves: rhbz#713961 - libsss_ldap segfault at login against OpenLDAP - Resolves: rhbz#713438 - sssd shuts down if inotify crashes- Resolves: rhbz#709081 - sssd.$arch should require sssd-client.$arch- Resolves: rhbz#709342 - Typo in negative cache notification for initgroups() - Resolves: rhbz#708009 - "renew_all_tgts" and "renew_handlers" messages are - being logged multiple times when the provider comes - back online - Resolves: rhbz#707997 - The IPA provider does not work with IPv6 - Resolves: rhbz#677327 - [RFE] Support overriding attribute value - Resolves: rhbz#692090 - SSSD is not populating nested groups in - Active Directory- Resolves: rhbz#707627 - Include valid "ldap_uri" formats in sssd-ldap man - page- Resolves: rhbz#707513 - Unable to authenticate users when username - contains "\0"- Resolves: rhbz#698723 - kpasswd fails when using sssd and - kadmin server != kdc server- Resolves: rhbz#707282 - latest sssd fails if ldap_default_authtok_type is - not mentioned - Resolves: rhbz#692404 - rfc2307bis groups are being enumerated even when the - gidNumber is out of the range of min_id,max_id. - Resolves: rhbz#699530 - Users with a local group as their primary GID are - denied access by the simple access provider - Resolves: rhbz#700172 - RFE: SSSD should support paged LDAP lookups - Resolves: rhbz#705434 - IPA provider fails initgroups() if user is not a - member of any group - Resolves: rhbz#703624 - SSSD's async resolver only tries the first - nameserver in /etc/resolv.conf- Resolves: rhbz#701700 - sssd client libraries use select() but should use - poll() instead- Related: rhbz#693818 - Automatic TGT renewal overwrites cached password - Fix segfault in TGT renewal- Related: rhbz#693818 - Automatic TGT renewal overwrites cached password - Fix typo causing build breakage- Resolves: rhbz#693818 - Automatic TGT renewal overwrites cached password- Resolves: rhbz#696972 - Filters not honoured against fully-qualified users- Resolves: rhbz#694146 - SSSD consumes GBs of RAM, possible memory leak- Related: rhbz#691678 - SSSD needs to fall back to 'cn' for GECOS - information- Related: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#694444 - Unable to resolve SRV record when called with - _srv_, in ldap_uri - Related: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#694783 - SSSD crashes during getent when anonymous bind is - disabled- Resolves: rhbz#692472 - Process /usr/libexec/sssd/sssd_be was killed by - signal 11 (SIGSEGV) - Fix is to not attempt to resolve nameless servers- Resolves: rhbz#691678 - SSSD needs to fall back to 'cn' for GECOS - information- Resolves: rhbz#690866 - Groups with a zero-length memberuid attribute can - cause SSSD to stop caching and responding to - requests- Resolves: rhbz#690131 - Traceback messages seen while interrupting - sss_obfuscate using ctrl+d - Resolves: rhbz#690421 - [abrt] sssd-1.2.1-28.el6_0.4: _talloc_free: Process - /usr/libexec/sssd/sssd_be was killed by signal 11 - (SIGSEGV)- Related: rhbz#683885 - SSSD should skip over groups with multiple names- Resolves: rhbz#683158 - SSSD breaks on RDNs with a comma in them - Resolves: rhbz#689886 - group memberships are not populated correctly during - IPA provider initgroups - Resolves: rhbz#683885 - SSSD should skip over groups with multiple names- Resolves: rhbz#683860 - Skip users and groups that have incomplete contents - Resolves: rhbz#688491 - authconfig fails when access_provider is set as krb5 - in sssd.conf- Resolves: rhbz#683255 - sudo/ldap lookup via sssd gets stuck for 5min - waiting on netgroup - Resolves: rhbz#683431 - sssd consumes 100% CPU - Related: rhbz#680440 - sssd does not handle kerberos server IP change- Related: rhbz#680440 - sssd does not handle kerberos server IP change - SSSD was staying with the old server if it was still online- Resolves: rhbz#682850 - IPA provider should use realm instead of ipa_domain - for base DN- Resolves: rhbz#682340 - sssd-be segmentation fault - ipa-client on - ipa-server - Resolves: rhbz#680440 - sssd does not handle kerberos server IP change - Resolves: rhbz#680442 - Dynamic DNS update fails if multiple servers are - given in ipa_server config option - Resolves: rhbz#680932 - Do not delete sysdb memberOf if there is no memberOf - attribute on the server - Resolves: rhbz#682807 - sssd_nss core dumps with certain lookups- Related: rhbz#678614 - SSSD needs to look at IPA's compat tree for netgroups - Related: rhbz#679082 - SSSD IPA provider should honor the krb5_realm option- Resolves: rhbz#679082 - SSSD IPA provider should honor the krb5_realm option - Resolves: rhbz#677318 - Does not read renewable ccache at startup- Resolves: rhbz#678593 - User information not updated on login for secondary - domains - Resolves: rhbz#678777 - IPA provider does not update removed group - memberships on initgroups- Resolves: rhbz#677588 - sssd crashes at the next tgt renewals it tries - Resolves: rhbz#678410 - name service caches names, so id command shows - recently deleted users - Resolves: rhbz#678614 - SSSD needs to look at IPA's compat tree for - netgroups- Resolves: rhbz#670511 - SSSD and sftp-only jailed users with pubkey login - Resolves: rhbz#675284 - "no matching rule" message logged on all successful - requests - Resolves: rhbz#676911 - SSSD attempts to use START_TLS over LDAPS for - authentication- Resolves: rhbz#674164 - sss_obfuscate fails if there's no domain named - "default" - Resolves: rhbz#674515 - -p option always uses empty string to obfuscate - password - Resolves: rhbz#674141 - Traceback call messages displayed while - "sss_obfuscate" command is executed as a non-root - user- Resolves: rhbz#674172 - Group members are not sanitized in nested group - processing - Put translated tool manpages into the sssd-tools subpackage- Related: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - Also add the updated ding-libs to the BuildRequires- Related: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - Explicitly require updated ding-libs- Resolves: rhbz#670259 - Refresh SSSD in 6.1 to 1.5.1 - New upstream release 1.5.1 - Addresses CVE-2010-4341 - DoS in sssd PAM responder can prevent logins - Vast performance improvements when enumerate = true - All PAM actions will now perform a forced initgroups lookup instead of just - a user information lookup - This guarantees that all group information is available to other - providers, such as the simple provider. - For backwards-compatibility, DNS lookups will also fall back to trying the - SSSD domain name as a DNS discovery domain. - Support for more password expiration policies in LDAP - 389 Directory Server - FreeIPA - ActiveDirectory - Support for ldap_tls_{cert,key,cipher_suite} config options - Assorted bugfixes- Add noverify to sssd.conf - Resolves: rhbz#627165 - TPS VerifyTest failure- Related: rhbz#644072 - Rebase SSSD to 1.5 - New upstream release 1.5.0 - Fixed issues with LDAP search filters that needed to be escaped - Add Kerberos FAST support on platforms that support it - Reduced verbosity of PAM_TEXT_INFO messages for cached credentials - Added a Kerberos access provider to honor .k5login - Addressed several thread-safety issues in the sss_client code - Improved support for delayed online Kerberos auth - Significantly reduced time between connecting to the network/VPN and - acquiring a TGT - Added feature for automatic Kerberos ticket renewal - Provides the kerberos ticket for long-lived processes or cron jobs - even when the user logs out - Added several new features to the LDAP access provider - Support for 'shadow' access control - Support for authorizedService access control - Ability to mix-and-match LDAP access control features - Added an option for a separate password-change LDAP server for those - platforms where LDAP referrals are not supported - Added support for manpage translations- Resolves: rhbz#660592 - SSSD shutdown sometimes hangs - Resolves: rhbz#660585 - getent passwd ' returns nothing if its - uidNumber gt 2147483647- Resolves: rhbz#659401 - SSSD shutdown sometimes hangs- Resolves: rhbz#645449 - 'getent passwd ' returns nothing if its - uidNumber gt 2147483647- Resolves: rhbz#658374 - sssd stops on upgrade- Resolves: rhbz#658158 - sssd stops on upgrade- Resolves: rhbz#649312 - SSSD will sometimes lose groups from the cache- Resolves: rhbz#649286 - SSSD will sometimes lose groups from the cache- Resolves: rhbz#637070 - the krb5 locator plugin isn't packaged for multilib - Resolves: rhbz#642412 - SSSD initgroups does not behave as expected- Resolves: rhbz#633406 - the krb5 locator plugin isn't packaged for multilib - Resolves: rhbz#633487 - SSSD initgroups does not behave as expected- Resolves: rhbz#633406 - the krb5 locator plugin isn't packaged for multilib- Resolves: rhbz#629949 - sssd stops on upgrade- Resolves: rhbz#625122 - GNOME Lock Screen unocks without a password- Resolves: rhbz#621307 - Password changes are broken on LDAP- Resolves: rhbz#617623 - SSSD suffers from serious performance issues on - initgroups calls- Resolves: rhbz#607233 - SSSD users cannot log in through GDM - - Real issue was that long-running services - - do not reconnect if sssd is restarted- Resolves: rhbz#591715 - sssd should emit warnings if there are problems with - /etc/krb5.keytab file- Resolves: rhbz#606836 - libcollection needs an soname bump before RHEL 6 - final - Resolves: rhbz#608661 - SASL with OpenLDAP server fails - Resolves: rhbz#608688 - SSSD doesn't properly request RootDSE attributes- New upstream bugfix release 1.2.1 - Resolves: rhbz#601770 - SSSD in RHEL 6.0 should ship with zero open Coverity - bugs. - Resolves: rhbz#603041 - Remove unnecessary option krb5_changepw_principal - Resolves: rhbz#604704 - authconfig should provide error with no trace back - if disabling sssd when sssd is not enabled - Resolves: rhbz#591873 - Connecting to the network after an offline kerberos - auth logs continuous error messages to sssd_ldap.log - Resolves: rhbz#596295 - Authentication fails for user from the second domain - when the same user name is filtered out from the - first domain - Related: rhbz#598559 - Update translation files for SSSD before RHEL 6 - final- Resolves: rhbz#593696 - Empty list of simple_allow_users causes sssd service - to fail while restart - Resolves: rhbz#600352 - Wrapping the value for "ldap_access_filter" in - parentheses causes ldap_search_ext to fail - Resolves: rhbz#600468 - Segfault in krb5_child - Related: rhbz#601770 - SSSD in RHEL 6.0 should ship with zero open Coverity - bugs.- Resolves: rhbz#598670 - Ccache file of a user is removed too early - Resolves: rhbz#599057 - Incomplete comparison of a service name in - IPA access provider - Resolves: rhbz#598496 - Failure with IPA access provider - Resolves: rhbz#599027 - Makefile typo causes SSSD not to use the - kernel keyring- New stable upstream version 1.2.0 - Support ServiceGroups for FreeIPA v2 HBAC rules - Fix long-standing issue with auth_provider = proxy - Better logging for TLS issues in LDAP - Resolves: rhbz#584001 - Rebase sssd to 1.2 - Resolves: rhbz#584017 - Unconfiguring sssd leaves KDC locator file - Resolves: rhbz#587384 - authconfig fails if krb5_kpasswd in sssd.conf - Resolves: rhbz#587743 - Need to replicate pam_ldap's pam_filter in sssd.conf - Resolves: rhbz#590134 - sssd: auth_provider = proxy regression - Resolves: rhbz#591131 - Kerberos provider needs to rewrite kdcinfo file when - going online - Resolves: rhbz#591136 - Change SSSD ipa BE to handle new structure of the - HBAC rule- Improve DEBUG logs for STARTTLS failures- New LDAP access provider allows for filtering user access by LDAP attribute - Reduced default timeout for detecting offline status with LDAP - GSSAPI ticket lifetime made configurable - Better offline->online transition support in Kerberos- Release new upstream version 1.1.91 - Enhancements when using SSSD with FreeIPA v2 - Support for deferred kinit - Support for DNS SRV records for failover- Bump up release number to avoid library sub-packages version issues with previous releases.- New upstream release 1.1.1 - Fixed the IPA provider (which was segfaulting at start) - Fixed a bug in the SSSDConfig API causing some options to revert to - their defaults - This impacted the Authconfig UI - Ensure that SASL binds to LDAP auto-retry when interrupted by a signal- Release SSSD 1.1.0 final - Fix two potential segfaults - Fix memory leak in monitor - Better error message for unusable confdb- Release candidate for SSSD 1.1 - Add simple access provider - Create subpackages for libcollection, libini_config, libdhash and librefarray - Support IPv6 - Support LDAP referrals - Fix cache issues - Better feedback from PAM when offline- Rebuild against new libtevent- Fix licenses in sources and on RPMs- Fix regression on 64-bit platforms- Fixes link error on platforms that do not do implicit linking - Fixes double-free segfault in PAM - Fixes double-free error in async resolver - Fixes support for TCP-based DNS lookups in async resolver - Fixes memory alignment issues on ARM processors - Manpage fixes- Fixes a bug in the failover code that prevented the SSSD from detecting when it went back online - Fixes a bug causing long (sometimes multiple-minute) waits for NSS requests - Several segfault bugfixes- Fix CVE-2010-0014- Patch SSSDConfig API to address - https://bugzilla.redhat.com/show_bug.cgi?id=549482- New upstream stable release 1.0.0- New upstream bugfix release 0.99.1- New upstream release 0.99.0- Fix segfault in sssd_pam when cache_credentials was enabled - Update the sample configuration - Fix upgrade issues caused by data provider service removal- Fix upgrade issues from old (pre-0.5.0) releases of SSSD- New upstream release 0.7.0- Fix missing file permissions for sssd-clients- Add SSSDConfig API - Update polish translation for 0.6.0 - Fix long timeout on ldap operation - Make dp requests more robust- Ensure that the configuration upgrade script always writes the config file with 0600 permissions - Eliminate an infinite loop in group enumerations- New upstream release 0.6.0- New upstream release 0.5.0- Fix for CVE-2009-2410 - Native SSSD users with no password set could log in without a password. (Patch by Stephen Gallagher)- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild- Fix a couple of segfaults that may happen on reload- add missing configure check that broke stopping the daemon - also fix default config to add a missing required option- latest upstream release. - also add a patch that fixes debugging output (potential segfault)- release out of the official 0.3.2 tarball- bugfix release 0.3.2 - includes previous release patches - change permissions of the /etc/sssd/sssd.conf to 0600- Add last minute bug fixes, found in testing the package- Version 0.3.1 - includes previous release patches- Try to fix build adding automake as an explicit BuildRequire - Add also a couple of last minute patches from upstream- Version 0.3.0 - Provides file based configuration and lots of improvements- Version 0.2.1- Version 0.2.0- package git snapshot- fixed items found during review - added initscript- added sss_client- Small cleanup and fixes in the spec file- Initial release (based on version 0.1.0 upstream code)  !"#$%&'()*+,-./0123456789:;<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[\]^_`abcacacacacacacacacacacacsdedededededededededededeesesesesesesesesesesesfrfrfrfrfrfrfrfrfrfrfrfrjajajajajajajajajajajanlptptukukukukukukukukukukukukuk1.13.3-60.el61.13.3-60.el6 sss_debuglevelsss_groupaddsss_groupdelsss_groupmodsss_groupshowsss_obfuscatesss_overridesss_seedsss_useraddsss_userdelsss_usermodsssd-tools-1.13.3COPYINGsss_rpcidmapd.5.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_groupdel.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_override.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gzsss_groupmod.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_ssh_authorizedkeys.1.gzsss_ssh_knownhostsproxy.1.gzsss_rpcidmapd.5.gzsss_debuglevel.8.gzsss_groupadd.8.gzsss_groupdel.8.gzsss_groupmod.8.gzsss_groupshow.8.gzsss_obfuscate.8.gzsss_seed.8.gzsss_useradd.8.gzsss_userdel.8.gzsss_usermod.8.gz/usr/sbin//usr/share/doc//usr/share/doc/sssd-tools-1.13.3//usr/share/man/ca/man5//usr/share/man/ca/man8//usr/share/man/cs/man8//usr/share/man/de/man1//usr/share/man/de/man8//usr/share/man/es/man1//usr/share/man/es/man8//usr/share/man/fr/man1//usr/share/man/fr/man8//usr/share/man/ja/man1//usr/share/man/ja/man8//usr/share/man/man8//usr/share/man/nl/man8//usr/share/man/pt/man8//usr/share/man/uk/man1//usr/share/man/uk/man5//usr/share/man/uk/man8/-O2 -g -pipe -Wall -Wp,-D_FORTIFY_SOURCE=2 -fexceptions -fstack-protector --param=ssp-buffer-size=4 -m32 -march=i686 -mtune=atom -fasynchronous-unwind-tablesdrpmxz2i686-redhat-linux-gnu?7zXZ !PH6 ]"k%w+p}:w{!zCB쫅_􎷎{8FIe}c2DT QMdL^qBɐrwqNW) 'ɭ]qk:}42mL\">Ang4xDHDwߺF jy+"Xض owAZIPUՑPAÖA#۔NxOߢso!m</ty\b]`Yݤ2M> _l,'Nòl)4J&YQ|vT֋7]onXGS _Uy;N*^̒޴;3#袓>*o|B}œꨦolэ).7Lvd|ٟ]neQ %\J50of/< &Ո%8we? ߟxa4vZ@4̹>^ ' v` 5ptb_HRZ TIeTQ7 YAn~,B~S!ty/`b\c-TlWk !fSu97-* q,4A%~U/˹rIњ" !pщvYjAsp(j dxv)jR "ר&,n$!̳}#+זe:~ ih!Tb Tu4'm]O1F`>PZby@iZ'h!=FV]>=!!uBKiH?+U#7Ҍ,J>QHsY:VA& 72_AntRcJܭ"p$)7Og6jL=f1iwyqyOz> @9m"ECCo7NQH뢫gRۆ]jt=tAwޡsTRg1cȅN U9av FKv2P$UlL O%9%Pǵ>khhbʿ4j{=y%XcMT֩<aI|: |&)-wfhc4s7$ɀ٩4`Y OWqcť#7jwX?&knʀC}|<#k-.f"]ߪQ9:b$̚bZ}4p4; T󑈆r|uφHc7Z !\jGtpBµN2"iٜ$-ڲPR}ruEJnb' QD9*$M*&7pT~ [ƏR(?ҏ1>t;=S^": d_l7p1quC9od6n5Cx\dPayqh ,O^ hEfD㟫@\J5V 0#\k%ݓR9@9ys򺏧 -tCg|V#1x%wRYJ((^էczRN-[^",'!rЭ9L5NH=6.uj2TR=9-Ԩj1Am(YxFN4cRY ĸp}o'BwCC*%0T4H?m{XޞtPJ\UJsAn=E_Tʌ8=Il;v+) )J~k *jP tSP-7x-;(L8K(蕍 ?5ըAڝ"~ i% _,y{D|/JRN?3*lJSPŘ?!LkayVO 39`Ofos7A3=1aL쁏hM,ivX}{~}HڟfzD8H[0ćz,67< ,ʗ ZqNyu=(l83ĸRV̉e@`=_0mõ3Az#Gj!+jɝ 9BsDijN]<)G?[zo^%y 'W ϗ{'?]D$s9gGTٓKg}?pj68 9N巊!bBC Âu.3~R>tF*Aw-=@~AZ `/Q0ļЗ*>] {cp dUMJ ?0r9ToA13ySui0ԉ 3=IȠ_AUUm OeLY i=, Չmo+]cw8)0M-(ݘ-G[f8Fu;>FzپS(Z|=giv3?NSV氞>|Z ] pVq^_1n> 1fV_ruW?Ѯƛ+S(7)E]P'4 rL{dWCZԤ[gQ#$~MM$oE5f1vvܘ >*CA` fHks 4_JBvc  L58 Pwb +ɉx"'b \zkvѷD _0d4LL_[T02#CvW]R#*¶(74w!dM{\חIFd`(0L({|rƤx[r׉yEyim82ÿ+Cb{228d$JF@꺿?5(K1>5 Gv#PEQB∊(+C@c`(JPjOs!ZE38r,1?YJ 3bTlI*_U+NT)4ď\ ǰWR HtV/}cvJ#=p#۰voalN鉁Ro.-4,% Vjؖ kҰfrEFnR e u3%E65U~&#Boi6@5,݈y\˷adlV\JaQw= xa=(y|!B!&GU"x|rV\N9tw%gN[Z~A0DOؓq~sLDadHqbmoa%C8mD(vVޅ !>uOJ?/y);Jpݤ8[_n`)W %dM+:yS{,s}IOwh=^3*UI;{ld^]@=}@"eXWNNBDLֈ]M $˗N[ѪP8YZxEg"laTʿ/줪u)[8PlQT)]o[y<*r~5'=W*JI~{sxW,Y5Ih3}UiqމRO$K6!O4GlV7D]b1=IP4,9>4? ^GFשF A꾄mP|32NLO>T)փ u@*!8[EXRkK{~TVC=!Ck៙VȐ\Rp1zCxdqVg(!1\/uK~$!tM"4fO}Eg*];$Td-;T x Gv,m76V>)h)׵&@-:gq7HdOL2[kNIF s{[x)fϨ>RLWTHN*t=?)eSn?:HLQT0(-L^`W=А?^v]2-c4 i/5ICRcUS݃e"֛(~@Aw{y ߧZ~PjlIf'݇ ಢm^ΧkG)%kj0~!uD]8br@C=a D:@vO*BLn[CDA*"'+d*; Ŕ'אּ,} 3lNmDmYg6(5%yB}~慢Qu^D6VQ_.\J.ު\_^ b2~}ďj-ț0Mq%d7b3%!.eןW{'m Ie? :Qn+TEmi]LW5]`A[Mf2\VmrldL5ݦnB<-5ef'bGu2,eE3; ;WۘIOe>8MgUYRn7uWK1;~a!8P3&#O{jK0HǦI )&R>ܟ̽+nRTÜج*Y,;;SO K 7Q`vyg)jR^Ӑ&<.{(qLYypݴ]kQr41ܨ-_O>uYܪ{G.{ ŅqԗZt<;[-zJs.3e88+A}'_$Л,z ]/r !89~:1,"HWX0r"Vv#+z{+Napujy0dž{v9\K Kt#6?xfw1E $_i@?xq]q1'?-IDʓa3;4U~!C.#\ѡ<֛ZT I?^~⩏0ù cbxRn?sܘ(:L;e%cU' aCdXM">vU&2!m5Fxjݿpb0M }F_tUfzs$DmNCE-%x_FGX"ɀ̢ C7,P}/}B,!{Z"jq||52aAX4"7~8К~L\QjxšN)AH䞲,*<wʣ]tҞҤڎ+n-3#>3 /2ah".(1X3CKGQfSc.s#ck1 ;$HMlBmXgُrW5rU&YmP,Z"ji$H`iצU7A8i*4%O Ud?pN}<޼4Dw|YM_ds~<wĔӸG4cKs0@e|ȇ&j*'YzC"c7BpE=*6MԐRُy囻2i>wˁ@׽HnX )ܸ6nx߰~b 95YX'b*60BQ1%r9@9MNw+⋵ <Kvܫp H!! ]=J 8]b\y,^ˢn!`D#cX/w(3RRa@x F=ԁ50к =LD] i#nfFhBCo]YDSng1& a }yJطu}П>֊Aؘ"l nd\㮿wQ\I{ IPT05l7;opd;v/{Rs` q$ *6!Q; dO.>VX nױCO?FK7c裮vv;Z}VQ-ƃXL)S0) qZ_3׺Dz\UecnT亭m8wȰngw'21 ͫOue+߮P ~Abj]Nd/BB rpF4{^S~ȡsŊfģյ f18# zF=L =C7 ΪE`CZiP?)D>v;]8, CH7)%?pq$jP/.*Y֒vҫNۂH[l&R)ZA@9~ ŷᨄW'Eѿ)uLJ(GA㞩rtꀢܹ~h7em`P$}?e1>wC#| <^$LG`Tt%VTx++n8j: G]qX}3ޭw.г4]ٗ imy H25~%֜A]N,@jwC7ᥡ$lndջ#yдKsH:ofy;r{TȨ#ACYm{wh.Jz*.ծ,u~Zf :Ι~7KgO_5;7ېr:OAnCCe<І8*QZwgiB`mj.U|qxX4ƨn=S#ySE}c+&!0ֽaH ^7H@s[*C1@S "QV;Q16͎z-Dt/m mtT$tFszi QOh2@ ]aX-0qoCF?c#m@sbվ5 1LɬzZ)VHܛң79 %E˞>&>> ߷$`aO ю޿DZ53G՟\fA$=SISZI!Ub1#æ8}cilz@6J0y^w־ĤQvm/8Uݵ\L+Թ=Xˑ+hG7Fugw,CCH_p-c6EMuՠ)5TC32 q% >j M tyU < vɂ3ߊd $0p^$yR1Y(DUWD ]S%ʿ;h99!3{׵^7a{TX=uzQ|#RYP<[@-*3ͷV1wb iXG74jj^U"Vn FH{a7beJqt;=-QVqEa+X~x{)fZQ3 =Z* .Y2"<~CMh%S&u[Q=&JMYOu4zN4l>| !KX/t$ֿK?Y0u8wY(^N@/О7g;(8w1U[d`-Hmq.l~%o Ō$;35BBsR=(|"܆ǟYٜ_Aj%a_JN9A]aF&TF.xezE65w|t!O1sWK%+[n7P] ^*!u|27xk5WK@)EJ9,=M@6Z)Ǟ*é,|ٓؔ^p"9f>&#):uEZxxz I.wdXHe3i=ۺjz;Qzi(Hnd*Xۅ/!Lnwjt9hG'gdZL9 䯰i8C0[|%UEy#(bI\Iw5aPDl݇/mY/'l.ٞK҆_kjo0UEx׏R$ ]v0ѻka3RBY=7g.Ί\刑4 33S\75=BΔfB?‚$74q~wy$xSmt=0r{iL`BZUlWk#U^g!D\qYҺ5w@[: Yp Žws5qp[3ZG;d>؁Jshh> }$i [PS2;- K/I|+Ij)= p XP/jXPgBRa ž%x_PrAz-&*Bw[k/Tt|Yߢ$DV =.z񳯛YaGZIblmp> 'jP{[ ly!{b6'oh @rYAU.@#05`A*x9}C>-&߶A;8Q"*.pyNEF=QJh%f}!S[X xA0'Q5ѐp'@j7a."oF[zаbq88{m2֦Ǜ$|DJh${ *BL +;Op:hِ#F78q} #lZ!;_wx㕉ȉ-Z@#eAčw[ds-^>٨"Y˂,F ;*{ qPrk%"pC^}anrPL;P+a/xq!_Fhlhu'T/^"iiaX:P0I_N^LtPR Qplh1qI+L2C>Fŧ?쿞hܲDa%GoaF#wd݅Vrf% 4(P.7 |W?G U E&Z|Eyewku N.%L?:~1wCDOF` >w5ɢ="Pbi'!\61OCWwȺ҃Vfr/T5 @eq_d2,+$ l8!l|$;0J6 K#pc.G` kԀI3|7gj~MF'L6z?8(!>>6k b00S+뢬l "oϵޛ{tPG5oЮ:E}*^cn2kd'FhEm,x2N u?ؕBwOvcjwX^HОWIiW%>&!r}؄>iu. ly)tn25xStw8C^@5fDry9 BU-3Z.ci!}0Cz9BK|%YߓM)+wD|| {NFjRF1ŧ@y.#y'磰ȁ+%V{ıb>]vLf2\Ȗ̔viڲPMh!犔\l+Swz{N֡\QGTEتqWp>sq>\IMs{v.n#d>/:*1,221Dዑ-TZ.J%]'o_x@1A. [@Bk[x.l oO287,_ 2kXzmo#xK} d/=}-D?/&#w3ڝ'Z^BC.42鬌ўohcmؿAbK5- ۨLTϫEhPŷѯ$C.ƗBdH1c&joФ1@GlGmܡ0f{@20 35ZŅf2";xmb6 lD}xWo5x}*cV$ZfCHYxKy>s;6Uw*ﳊWl#'gu61>CP`8H[|]D` `uERViL=sPZ.ٚ$̠T=IVJh1^{QA0DSD)և 2)HTSS)XQ;&K?$)mQ/|H6D&0x` 3sxD-#\ؔT&Gx/xAR?uMژY-p2na2^ڊ]9-z˭_kԫs̆ew'[=~DKsx21vN3/ EoD\I_Q_>*+[QqV-RA%т6HLЂ^w}= N_%6s{ٲH&ZԖǖ1a xICetywݴu/Iv#?$@_٩Y3B%{R]\m+iK(|G>px+J\+?I1]֭G݆Znh$=Z-Fk\Ed(uo %\hXRN,\˰A=F D/2.@mZtw Fa2Ј}XILT޲T{dq/O:a ޒʿ% I9”ʋq {Ě@Z6Kmo2Sz )mwFIY&nB4zK-S'5-M7$yGq?NMveXua2f)K8ك{\HQE^9YI[I%͜M/ĄY0 Vٞib-hmQSZ#:_"$3zqu YgYC_G9e2IreMRo;fff ~ja x(\GxТ! Щ {X'PZ8y -"pK]){cO h)}S'}a>^F5@<hNR#rLTe}=sywg ,QW4..')HYծc\+Kqv~Bb`{ңbEv3X,3[=-w H:y] ޙՏ TЅ8)"?Щ¨w9r SExF17v3/y>0B_)LY䢜*>{ϓ)W{)PV;RDCT0־dۻ>|=oj1u~ynwaeWc&kٽ%f\3ΊD52α\pR"iNT3"EjU?m赼3Q/Wjr>ٔE~wb7.o ߡH* <;Lwre/DVY0F{Uӷ :c/3H0IMbYH}cCIȀn nYY:6l,+a4BHȜ!* ~R)#{(̺`_|35x)Z(d%*Zc428e&׹|8_UQ5&vz Cj$:Q/K=_Bc%c9>h @(|Ό#e#أ_8*dž[2K-_1͕/O{&d561XM JPlUS_L) ҭ3X? ~a041aFmA`R H9sިC !^(H#5_f͵~jHD'ܻhۜ$^b5րJ+]VUف VvlnWyFM2A`{)TU13ƥ״ #h:[oaPF[c^lvw^azWl"?!u&2. YJ#+ YLRu\#414xt(~`l=z 䇃13I-DjtuucRvSPpC2>tZ7gpPΠTB:yF8wr+s xWkoR`tWrJgjQ̩ *cp9h1tUܦ(ċ^tG 1o}cpBx <,$1mJjxc)r\? u[. mHW} Lk&%3}<ֹ^ hD^V?k B'5CVM@2\y)?/  "cA0k$x<|>E]NWlA(=S%¾Zq+,p()x+OI9P݌cvM-~oқ†.'m^F,6@WZe;e|#g %>`óux5Þ ,~$޷ zYNZÍ"ݿr{>2cWԇxA sOQ0R ].Zl9o]gb|o AP%u{/BcgmpP$ؗ#,nZrG$oso ]/=hJRڭiO gINk`#AD3҃4M9 FƦTBIkf0ct2J2\}R]K&.GCL$qdI匌c ۨBNFhڤ4kL pޛF`;ҝYczнF7/{@T.Pam/mJO6:[RsjUAb} >@:"mz4NO?aƌ(;C~ \Uuldhm\ e Uh^n&2D_SJ[a3Bkk]r:cd&?lP,m8!"oX}7@[>R4ߘNo~ySMwW+6UtvQ\H4S7;1xsD*?iXo3aUm"Sd[Jn|{`_Q+qf_XvRkZY%H+)G7x|[ #}t~{8DPQ5'ﺌeRs+Whz׃*llsǂb|TXaZ64C`[2MO ЪM A+SCMSX&|}*_KJwxZFԼ(ñ /{/6eE{`mP헩~Oa7mcx/#U]8H㯸#d_);dd1-$YARyuy5FRk0{*x0YgOH8f *6\Gր|sqb<-+\EwλSXlMP *UԵ`uY,Ö J"%lƛpꊅmj'*iaRG;f{\o_mq]?4.zِ 6(6Q܍wd$ !U1* ϐG}:ޏ89i]2QDr E6`YbV9GD~fZ|NB:6a v#XZ%!sd2wgӍGe(abt GkӚ'L]o-&4EZSEM+^jK)7c^22PsZj1O~݄۹۝ҵYdϽԮ Y7+;p?GdnĈE7ui 'Q[mد' ܠ;0'(E򪜿'C`+ QM/ka.4f=`¶HF0P L6J_`hEReW,6In`%ZZ}j,0>\8Z? "׷Idf-ϾF9eR6f`b|L'!_̓7j(1z̻=(",i@;8J0O[O* a->RyҊd@nZM8Cȸ04'()OʫmdeHEL Qz3*f`!3bZ_Q?c#O=<B[)ÉWiFs9!OSv ה]D1uOe'"qÉn}YZbD1BTqx~flQyK̳2pAT=X 6K{;$w MdMZ\\JA}Am2JlI!}dwh9䱓/)Y+0]8D{jd])|j i+ gP`Z@$Zo2pw "CDI_"LrfnI&l Pՠ0 %tn6倢H ~$@:[fW\hX͞ʥ=WEZDwe:79stvHƇ#fè ͨuBI& ?4FX7^AbJ5c/RQTA'ϵҢy}/[=|aXcu@(qt?PI?kIR/; x5BLxd=leL&/hTOfoQ g\^a߮zr\ aoyw.ˠp :y˵6;~{ T]i)FqVaLvDqD lf)9yN:8#.^V5@MB$3bk qB#I|KM0 '7> 169[I{n&ZB(;M:L.R-J&) u!j j*2SP1$>8d J| aFFAS,%FF8~f%I݂֭k1Dy3=f{x[DԾZ:n#H.fku-t tP2Rsջ^&м>QSޟ,7ÅoU$vT3;Zs_VWޏv-އ%|&QNUn@w{%-W؏F;#HvGIwI96bA`\.0ܜ4y] +ɱYt̅zkvcBTfs # p&%"ThPq|يLDp-0 NVs^XTc#k$Ausب.N, NAL$\y,sʓ(h9JPz[u5s?0پ]*|EM \NZ)Y%:g. b |m4 y}%- u^a:}`κ:f]^ſPf$ppe ؚvD V//4PXHejo'6@_NIS b残lK \nWN5h,iI8y^dLú 9:vݻ;Rf0T,ӹt)O^yEz4>vz͚,U<Vt`iI;##-X@V9T1q,"Wt[E\'6kU;n}m!3I+Xw>D}0D˅nҦ|Bw)>O+lt } D͡yE'GYӛ +=g&=צmf߸MK 90)KqJy?_&IU&fޔzuMV!E/Uͳ]2kI@y1{… Gvb󉏦+F k|;N_-¿?"UԐ"r|S%g-E)~LR(&sUsP۸)d̲ݖ y 3ꏝE(n{K)p0_qZe#zL,%hm~5إ9Mkݓu/*@_廻^t.`7V$}qj.@-E,۠0H '֩hO")baQ^t& RAU %70>'_Q9a$\*s6]mu6b'ĵli4y~:j: 04i+[dZ[HO&ӗTs5v#YUP>"L~ۛ<#1T7/ @a'Kf3 (!u~t>MZ[' ŊwqV 320'}c^Ev# S7ҙvb5t0HfxCV,n.]{rxŰRЮ7b?+Lnhj{E=xR XW;_=\7N$ֳZ jqu v9їyfYtx0Fu[DK&a9=(Fr+0e)bCьI:}=L\¯ O`#G{Q_F[TaIDK ${+jh]OCŒPZ`-Ɗ!hJذ r|<;w)ASCy(P`sq;{vi`Nbyh4ϊCyWq@QB_f VOOaq ξɎ1c0o2FlOS|y] _##$]$_@{?1e(cF!/?f8V5{|}՞ZujF .F,,vAZ<>.ƎLv\C9)^5ƖvdMT akZ86Ȫ&s'g1yìbQA\%4 #5 An{ FgvP=Q#: lJR ȱ?@-(mudua^wrkT*5[>4WfIi,B:ԇ:SXjCq X>r-F<LaDrPL_W%gf!y 3 _J(ʨ-affցN͉/%]IfZI,V8# !eFh 3CaW#1 H'\xPr\DA~C^bj!t(Sp:;qNr_Z!fU,! [[I1(TLۈ"?M2 W;vɋVT(cqʔc c;m_lVӽ#*j0g=@nX+3Ǔ\oNj8ZƮ:Rľ oTZ7mA]>|lazk3EzkCMprD'ʴ^ԡ9EKH!Ahtn8U: 4 +uvB^5ǜ:_@%YIUKz`X6g&Ųv,sʋsz?L+\jqh4UR-GS[7.?tr7h.>[A6^N-"ڏ"ȢENkӟYܲnj9hSȝ<<3?g󽐎 C-)~zKa󠀲-'.||mЊ{xĝ8ajZm;OLe GE릐'ajDN14;I_P3zf~aS0)DOBp&iå.8/_20荅);,Pǎ!nP`ʧGaQM)&T@e`PQ7܎9B J&M\c 5 ??{O3ouZ|J:SRAn}1F=I{'.D% D57/::cy歫[0@Dnrm$6$B5Rݡ'azٺF,.*_\lQhw`[H nJ?FyBf60ξ/4㔨& T@?آBE>Uk$8Y5荴b hsH'M\cK~m;kgDoD]qo2v\aVq\uRӅл!2RhFJtj5+xv(g_j%8N^ 0^ I 2OAAEt2+rJ"[oqH/Q@!Zy˸' #O%F-% tK5{MPg v mc'3M$ -l/:fS:Ļpa\VwccFIѻ0#MN-') u 2_Įftxd$%"1Y|5% Jh٫B_h OMk@\¹b-.VMZtO j6bHIt rBz62ѕiȔUw ̢m)sLh:ݞKO&Xn #(#GAKR{1qɘX78D{V#[8QmQ.#vx_fؓy.wۮ}WbnjT Nc5MJb`ߋ1IApgWbUZSfJwX*!})y(e,9|'Ѽ@jNEpP!栓.>3X:}L\i5|7UzR O\"qޙ—'e8o:sr!ˎ1*UZlS_Uqv(˓>G-vhvA)9! ,qY_'T#yRF2\+4>843%@Ng?lE,Qqt2[Xq4Zl3ȫFztX3ԛt\dA3_#6a;-ᰁ.l$>CzfCJ3Ϣȝz)BƠ"%St^\; {q*kXfAǖӃ! &/B4.PcgS߲JJC51BxS:Cx>4~=Z K4Lh`_ ^od M6 *TCQ tX D LIe (#?H?AʺKoCCshw<$J{>sޥO \\PPZطʮQ=c(8N {l}e9GʤM{G*9v6OXYO5.Rb3hDሺfht} I8.nݺV< "$l" & #>>H$ &MqvJ-$K56fpfiwwww`JO{Dޤvi k^*ң&u:qtO1bBmqX8B yq}w(?xY:CD'jYLͲs%\= fI|Ň*QBCtU3u49+LL}:Y ka_s[nɡufx":GO2@9',*/k(#ZR rگvig[Of MӮ;My2(7pafQ7W;x|}O^ˑ&׷VݸS,2^bziMŎ2~Id4}W[16Y{#g-접zf^s\FNSrSE{coKr Gaӝ YwN7g~@9&| .mhO|ŇW)9¬77`@j% ^/*k< jۚLOܣu]HR=Dx1Y?.VI*1-ՙ!ٜ W}Ϊ`y%B Ge1V:KsZ?G^ʔ'( 䋭)@ $M:0,eHw,|٤Mf61qL `{{T4'ipV qF,b앩׭Ynwt@p+vcvzBjDrtۦM;u<-aXN mSN\=s8weUB%6hW5<`rwS~"0С+ES*S(s+yWmR0Dy֒i%|p<mɍw[ 6T)q:@T98~ؾH+|`G XINJfݖQьtL9P=ujUpc_}>!̐1a\<}?ݢBcZ_Ď\Y"}՘N_H }!Uj'W{֠ÚH R!їEE0W6]|so}q, w>8,ª=1pYq%;Laff #N~B)q^e]b0>[NRz 㤝z$8 v'O䫜RumHǢC)ۓG1[*I_(Jqh0?laNU0 rњqѿf^ (j>YCG|:.I;ێ=.swwwD\vI?.*W+̈BN;|BZnݩB&؂nNp9->=8c¯,9Qe`!6L[F.R]:qa$*{-YY^C0[$V_˶Wׂ8`nF=|e\eM*mTm$' &|  Z7/#k<."9|qMӊ.D "|ᨭioxMnyyGtS}cO'L{V*{ ӳ;/FA3;'U\$r3pU^qD}y׃i Op=yu>j^ΧT=v]-+n"!=mj#i?er5goc)x &@ڋAm"06:Rr^hѤ6gVcky'͋{]g\j]zې[c٭ˋ%h S;jEAޖ C\_}CX&~kTe%5QTZAyqQ j3oH(s@hx\9qߑ]D]"ʊ7.^ձ9<ӹ{;X+ewKsvo5?d_togG'O,o59ߩ H<~*Aܫ6I$LD-7Y4CyEד{0LNY/tf;*bv- ]LU2Ŭ"W[(ha` k$R<_$%ص%'l X\1i+W~KZ4{MM 5,902F!ִ&ȀN "z㞕{P>? ̀T,(G\}^F9niD'>'(J9#q99(@?Q#8ʤOᓋ֤v@᥁ `28P3PCܷST 47v#7SBdraP̈Q½E+&ox灘[WdЄAڞm(L:h(~壔,l yL 6: X\Eos[50ΐe4d"IznM,bKόJd +k+ԗwُN>mZQj,c1z> 8xGɊle6>ghn֨LgΤ tKi a!_|!Б[P3}/Ldy ּ漐 D+ ΍[U  &צٯLjhWA1th!ec(Pd)LլJ6v գUd6SXdoMX1kkA.&̀RJB}wX2,26~[4PwBaXFߗՀ1mߓu%˲AvSO 2U3W֐{jRڭZX୔!WW'elhg&'fR^mI蓝$աP3В9:&L&V"L|K7Uu_J f?{hd.x|[OC=6LStRwO3  ņ{$c8ԁWsE]R*;j6@ʭ={=_q&.mE!lcL]K# aRt@i B4iQ_;JǗגtZ8s=@Rvgv: k_k!CBFkkV1A?FvjKn&&]<_*]l YIw="͛k Zm?vnwʶF3OKH󝠨#SBkMt%8 $;+873aqXC&?$IfPyЗA ȢeƛaNgN^5U*\#U5AY|+!PCEg¦_B~Ib߅V$u\%{x]4 sp8+]@h\N%@: tY#p]39fy|_ڃ82eLCҊLDno]I9ՙeͿaYT?n cv#Jx8݂N"dۃ'RAu9 =֊f=J%A\]vѠKf3+j7ؐso_./*K-ukJSԌn4BO#TAύe2>5f8["+"Lڹ<(mR {#;KS_\|Rl"Sk05oMd3bIMlavMD>oCR xnA& ]ne9=:.K&_7-·ۙ-m ,łv[a<̥gpF`Է ֔oz=$+YHXur0x#?p.҄epE8@Hf9IH`  "l Ur|_l4(A"deՈmo_P"!A=Hf; L) 2;\8!&ɸ !(_/w-G[f ZDZSBfZT4P ̻;߳>xfHȞ z vs-e?+vbk3Z ;)*MHm`yCsg^SǕs0T Eɽ@;MCda7$ԂhzϛB# ) rpP;;jh6g$%S1]7AQD`h-~$5D=oUVn5'4.zY{Ε|L)+lp5tctu3>wrL3^{km=8[Zf:XL+ށ+6 _aSLj `O/>|yP7O.T`V@uMXᆚ^wFE!Lt*O*1tZ^[w= O3>V̟{er99BYd 79^?6LYltI#NB4g?u@9&3$s@P% .P>Jz@~8`'u9-g3b(VwkVqt1IN}jz'bqtLd]g)tC^{@ƞtm6/r */[4i܉T-mɃaT)@HY@QG\nev}gyDcIީrM2@D4\V#A +0Jz RT {$62 |O&"'VcTYĜLsSƒݒz~d0=Sk n/;L#1 %&ad"HK6!t0^·&Qj xF %~|DZjc΁߾x +kW-VEqNDL P39+g<nHrZҏ[ա/T\c6xvBX- b)"Pö4;/{F)Z#o \;Պ)L_ tHѿ& =t0o*-&鶯 m ؤeX {&>V2ѻs'LvYƶ! rwkUC2*GKZrV["^(H W&: TLd&5^kߵ, ̬ꀣ9ʆ5?LkVQ$ojk?m3W5umSZ> =V((R5tf$m䲐9Z/Xaaf"vVQ;Y%]AQb.MXoPu0˅d'.\(,azUеhm~W~]YTl=##bR8&.r ڠE#ބ s\ Zy )`+&q.!5WIXil= k 9>d(a.e|T o;5vXm zEƾNl!ɓ}{P&zv9AV\oO@I}T5`/a'bq1G\$,m|x7<*KZe`/HN-jLB~q|]GL%̷p=/?`ՑOm^G ic?m/awTJD["f?1tpS%K Rmļ&lAݹ {TXήw_E{#u}Gt9#fgIsUvX   Q@^榟GtZ"Cu90)ab;rVPi$((MFPLN%TA6(ٯa£&Ƈ*. ^|~ I{B yʶr a.Xu@3mD0 )] )$dT- vȖ!pnR9 dqZWKsqя{``  eQnӖp¼fkR0(*Ş 4mHm _-Yk\URW-D~aZ Ia30Xti>`j%ۀƐY$O"ʪ9N o v2x.G@Wgw/Ad纕3}o8q|RNRhWԆc37HV03Tw?}+yrjsw @OLJ^4mxsiwł<._k eU C ~3yPuĒMأi>+*R~#Co(~b֭cs<'8OŃ W=@UE@d63*恘v4Ł[yCpP s!Dl/Bӹ\-*iSV[fH 9.<:͢HjeMޕcJ?݊g7^4Mo hE#zRl: ]ɰvA!語QG;0D΂^=SؚU=뻷"Dac(\Ka2[45'橙IH3oRyau8дw[;~^VYN( vi ޯ"cDŽOfm9 ڶ{n'n#+@fmsRcaztAu1'9zQr1ŃuNJbͅ7rx8+K; znad1 vYS)ף6H,idUi-j4oӑC))+( 8K&.S5y h0y a{(jҧTP& 3oZ juH,'&4Axi7Nb8'`}s[ZPEp=$u]zln\×UpGOQQt ^u;o#>GP G*W^ Os?jpVBp-]~b?>ŝc|JcE.FYՍt,ЬW걤6EeAFyHHJ8Heݵx7p ϖe6fý==c.sZ;tu28wAK5YMn$"%L 0qRzu5h:Ǖ1XxC{܌=H0'>nΞ݇$meT=ʲ.dpS@4~EpypCzVKܿ[KK̴x`Fqq,mѺ`?D}-/B3ݺݬgR%^]en>z1e:wGXA7 mj"0Aï^ ݻkn3{eq|p9Mv[M_1?,kPw/ E>elʻw`Qv9Zq9N~oSmXrIr=`^z t. 7E}cz*İWKw/0%D 5ڥ37"fVCV񈧂Pʿ4ih-WK ܸB[8U8aY{!Ҭ^cH{o&}_gennT$}BEMִ ́4#6coΝϨllJD3hƝuvMtW459/iƝ+SԸYclK"%]o TبŠA$0aCe:}+,+|G3iHx]ua<2x2w' ՑyKmZ%ӨnOR90҃KXOJi~ؚ7ydKƓ0 nJ_=! ,gl[:[cX9A0I3i %*`At"ݒS]"va_@9JF;2;/pzN_;^4+rDQaAQGdCbyPAg_R`>˭ɎS(kG.4rp<1"㴌NN\e}zVX}XWD_)Iaoe!^ƝZ#ejoEș̣hnVClS«ձ﷽̔t۶w6-f 0JC\waXkJ_qڥbF3݂Y$$U] S_T˨(zQjs'UƬ*E, 86? [:4P}0m bA<>с%xkz0r:?Q{`b9mPc!.,|[\snPtҎ$kQDP:@z}ۯ S4֢w\񬈁ki;vk &1_8!0\^M}2"&L o?3n\$Pl(/ME HG\ 56#cőQ 'K$Z r*p;s)MW+NjI@u Vƺ76ذu@½ZC܅}'fĻ,ѱuOy.ऽ?ND~M@.B !to%ZAAa.G5?7izDI P'阄VjZ -(-O9h< vb/=mf< yo;WgQ])6"It=jlTƎMḑ8}`FE?- Hjh@,s=Z!!|P|BԀf l客v5pPU@б/7ӽC+1 \~La%)Lg$[,=k \曉oMi (8xx,> paIfq@ȓ?7TpgQgCfzPJ*mZ[72*O,dҊwB: -= w{2?ٲ_m/*\dG4#l}Z@KZuqOVV]/'d4hlIq9z/NőA| fH44 |g) ot_uYYa#ޤY~8`\bv&,@`>=\S`6u,Ԕ4"ɏŰ|$+PT 8``Kb]M[u|2$h844- Ģnum!V|0v6% vqch\A-CEÛ%/3-5{~5OC'F T;-ۉk'L) ɶhwcLn0c;aQvMw8R,moK$֬QӋEλ żR?.P4oiefaIոTpH_zz=[N>GcO t5C!Fh/d7aƗH? _Bۛyʯ :){*ЍMrM(3A2:] oO-=F57ǖ{?议^⧡l]EWTZzEIF#_Gz;)I:˻'M3YA_?$i"[4TTHIv/c%Unߑ Ϊ=7Ѻ5<%xiX$%+\7vF^r)4H`kV.gf+A+pyy}ݔclWɵe- :|K]Ҹo1ج̭Oodv"֫ţ%Ҋ]XX0S uP"V_I]U _ql$x:Ps@yFC֧| ,F" &HƛWGVe\ o*h `PS`ޣ/~Vcj"tn8iX$aO,HƩl=Rd" `ӕ4W%@\[N1T=Ioau2١$Лލg?o#az_珠)a|1 @ryZ+A~G6%#H) NƿLKa%qiZ!n Mfz7ݏR%DMl40ҊCFPt_2oK~+@4AW"*htOmD2L;_d6ʟz} ӟUY[7ixB ~Z4`]>MPb]]ECciLӔRf?jxI`ohC0JfF^/^GTƜ o\J=kF6LIve`/dѰ7%SQ ڔd'ggS Q]33 m{*M%&|g,|VDcl߸td~=!6"#咙\#&չv޶馪d2ťAkSHęx.߂)8%}n9I-X~Eo}籗 e:'LrF.7V{VVB#>#v ku:7oԏ*@%TҏV.4QSM]#]BhɎ؂J1/[NdMpIٔ?(8ǐЙD2 GR d`5Spj)å8B"UH󿁘JR-2呓D|C.I'JOlJ4kw7D7h ! :E0rj Ӗ3;4VYblC+$mu9&O[?sf6f*xVa|rT)lmzI1LƩ¿3 7?k%U) B BcwJ}3#ǡr@^k,3Dg/ Ua=z/=MX}9 gҥWQ%>RE]Nvxq9BY8uxaiڂ$M@ go?[Q?¤Fe4ۈWyAJoFLR:x4w/Pb2\GaSwO8DLՄaQz[&0OU8UH:jZ{Vegʤ iΓS %u}pHAdo5M۾@ډou9Gz3im< _"łpЦg]Z3~e &=nQhdk^F6&L;wuT/b%rm4rL Qӣd;\)P \lbU8: n].?m["CVb@Y |{4磿[vJhڲ!3֡&r%N9Y*LD%:$kć+o0φQ̧w^ nEcb/gqJU2呙 *uU@$])51{aLT ᵗD$[r[ i >W-ubLC٪n84o޻ F3WYkGS z,|TJYhZuw. $nwGZ5>B7ZPm0"XLX }kz"F,iSrW#C̞^B߫L'|Ŵ}Nk +D\EM*VRZ5`]}r蕂Yq=x6ipH, Vq_*k@P{86:pcvI .fÈP_,:@rP&k^ |?pL3sq AVCvF0Wg,]p^.˳MB 7m\wЪWzchȦXrWK1@eI}EEj|_\h*ݓ"\x1[^`y a/U|4Fmo ,v$`o,U,RiCnUbz.ZJ C^^'.sBPd}/Dj!GIY4$ k$&M [H}uHv)ړ 'ѧL)2:.@|v5WsZ-:=KXְ}r}R֝g0-1f!^k ( 5Uv_%$T0nH[R(YOw$Bu`Cdhmvm$+V(6y}c|kEqEYk$QQcǁKVErjjIy7;sԙ(Ω4lj%ݍ| 6e=j0dkf}O6{VPU`ON=cF|JRb00oA"R<[H@/Kk<ʨ*mpfXwHp;wo$ʼ&ῳ=ͯ; ޛa) tS#43g45)#[\s {/ wkID`犟k;&S~د+{+~Ό.Np#ԉu3=?5:$⠸ϻχneA$yݚ: X3']6Xy2N%yG/ ^ qӂJs0& )@0";*2 }+KKwB}^LLƮq_W7IZs!LM#0?фm @hXxbLVG e@Ѝj!~$[DXhni+-Q}9c@ <$ ^Z͑뚇u[ۊbm/ƅs;1{sv;!Y@/ ԈK?-sބw9"OS3!U\G4~N79.]|ӻ ,G`.;џ0ڒJ>P5Ӄ\8 /3ӁYL*=Q7єem("}F/4|AmNO߻!(F;[']#1-̇6CkHvM+yTH5`6˓y-&UDWL%sY5.=uMA9pL9-2pTuݐ ۭw-L{Q-H&jDԭx#O=߽ծ蘠Q&KiS~XdM큃Mn߉zQ Nx3ՆpC]uSuw}Xccpܤk xRPޮI<Ԃkhncڷ'M.w?6:ACo:ޖ@`B9 &w6h {Z d2QJ˚r^dhUmh~:>!=WhŃ%xGa6;O`Ԥl 4Z7@KGJ|j((dRΦwLDN. J!TCظ/=^Z0Փ>6(w71qSdПS\UWyZ[EȺxJªzVPA|Xbnjwv'0t5wc &QZae$궜^GޜqɄ:Xo&\5Zع~yG+Xb!wU͒Q]e?%/g:4:gVv ~~("mP*- <'W'z./ZhZ l2 $nL}coW[-kOlaZHpsTԖc %Zt'hV ȉ"aYc\hJ^o9)~`\+a^LU&8eR5*¶|JFzec{=~ :(dS;=G3ty8g֊_8#哓ݷ)ь"8FnM2&_}B,g'm-߻AbËp6U~Tf7=%>u@EA EyMNΚ(ͪ«&O d=1vn+-(S C u]B4֝a-:7,5(GK-?_kȈ<|6o. ]nǿ9Z{8[tais*E{Fdr{uSl,-3H.z`9`H?Pkx}}iMp>"d1`d@W_$榘<r~yl/񝽌]G+(X&)ŵrnT*$E65;y >{X+g#kX^6l 3֛b_Úꄏ%[{{zXC` E) .,2uӟfi2/x&&og#W-]K}lLr4h7L ąTA8퓬R)\ pcg:F=7˘)=k^kR=^ꓒj?L\5,3E z`s+)whz},Lc)y]9)Ю^C" yX`dBNR`/Ԡ _Q' ZLW0:Y6z9A\_Uu^7A ՀGI%`8RwSbأ$:fL*ʴ0^;$! ,6Mln5az Pr$,=Ma,*#j|XĺI t1}$"xc´U+Pp gTY`nK #p,(dV>PidV6rg/}(V4@ޡ'*r=ts9Rmvȩ0yaKr6G޻랗w+Mԛ] 5[P Zh'=?􊧇c _Tw adUhc⨚%+1`_@1eHClIuWW$uv,Auxy)0>/!ٜҹl9}89_DK>wvKO7$P@7F9zźơ2sbyhΉkҷ4@#a,fU7 qvDևhو7j/а (mo@ 4ou aY3 Q׷cFo#ԍt Ϸ^NW.: ХUB$71m\*nAt?fՀCdVηWϭY(X )Ȋ? :c|43sKդDPEjIW^S E@RX5)~pmZ&LVN#xvMl9MS$T/LdipfԨ7tzp2lٞ}Y B&At@HP&(8f1\L$? \;O a/盗TZ]?k{3^f+5")"b6oJ=# =2z܊ΠGT}L` Rrv↛p>?*h i+ORQb5.Q]Lo&M:d;-DVUQ3QoA N΀>`H'/5qZix5d!ɫ)q\AEjPG)h V/@Tl<%t}.X*yu!-Vt!FoWLj9]ޣo SMhhUXfj$DnDȝܻ2bLˬ{Oahn05"5 ]Z,e>/ UapQ+L4nP3b }ݧ?SRV J<`kI,+*nFxpB®dGњ9v31I?kRi%l=S.}|!BjڦLn1{wvR~TX,K_/N&d^*f驜Q J+魱TDFlg,|;{EtVeTn%ܤ }票NԛJA+"?'WUdøU|pH08=|EYe:%dlǭjNUUq)i񢦓ZǏJqhy'Gԟ!O3xZeAMsxb:$IgaUkռ_T Ϥ"6H.ڹEC1k=EAf#.!2"#~,``A|jZNFy)]& }=87R l`d iNNe b>tSah$I~'TUOoAh~b5u8/Hy=2GOD?EoC06B j'WaÁX=S/I;1tY7o "1\k.r D\-ll+t^Sg0Z@ !BCj&Y1;! r('SY# J+\m5 ߱mA q1t%d&+ w3Gv,.IGoMW$B"?'WLm]jbeBjDL7P2 BgS|fj!dn:gEՑ&wSA{. 36"*h$='y}GvH0@xR @b.Q *&{sNa2ԏkTZ @Wy͕R#&uu)za?{?#Vi[Y).ϡkU2Ǧu7$A:oiQ\w NWEm nDoUTG979jGg@PE XTG{8N[3s_(TlS b"Kf#S3$8XѮMi:Q2HA1(UPsZS믃j5A1ɶ(!9_K1P 4I@.K vP HnQRqT1v@="Fꖚ/-(M0t&i\8XO[w<€%zp sr13L- EE|9 Ξ&u)<&Vy|x42țYrto\q0qP[(7TNrjŅf!^a@"R^Jdz9<֊ 1;Iw6|XZ9oMr̵cjxz~T/!Qxk7N)5W@>dGlE5ʚTjUte9G8\֓aQEI %[n#v17EմP"H/Ϊ  v(Jp2~YFcYj:##H1(.\-S~G;m>M:CjOЅxW#3y]==3.8@'ҁ-ׇB,PI}*KIZP]#fdpbDg(N'Q)͓u^NU|g}b4!W+ml1"MW1կSg-ItI KoFo|՛^הGc&CݪpxjE-\ k߀ڤ$qp~  "A.=Nպ1L=Ȑ{, C͘`TKAUkǺ~@,m?<+q\`ɿ0o}?'P1jMYftdZ 1~X,.lJf(2BfX!v˜6#qZܤoHLFƅEȚ4[J{\wc6 z/b=?b+ O_%hўO*T2v`!6g=Вie iDWh aeXxnr:+R-*Oe,f![c bRb4!mf>M;7&6k|,n_!ب,gsl;;⵽575/`7*cn ipQKC $ghCZz[0/$<8C WiJW, +( r: fvn`fq61x9IIfmbhM=A6 [P `tז$(3&:Mhycp{ ;]W}H!ƩZ$j4cC%NƒE]&ۖ=Nv#mA^u.֚+_*ۖRlV AlP4qެG6O.%OǫG+XqT$z $, +COq՗u,rhuƿd[qlHS(jdL?no_J0/o2b 2K RS|X-n dL/oPA:;t&?|4SEDCr =O:7Mw 7uܙք6NeziwOrDE0Q [|kCFp=Qׅ N~@2ǚ5 +ݯ0"Hz쓕`Zj$ k,V)IL\sTԮpadncd:iԌ1Nǃe0~,? eM'\LQ24*`>.F%HD}tZėgqce ^ x{6 az`ל̵w"ϒ5ނϐ{{W2'~7HgT$P{0O:\M)b.ţ^n4rk?1r2LtFH }hZcR\ifS1w`(h'Aw3_tԂ`@S,_? b_p84M4؉i2aoڱ+%L˴8R-v¯-zTkrn\1L⇃TNnsIEA -f,[UAL~-% 1 I5#eNϽ5C@',,2P.@ߙO0.0N8>$JFcm9dIf.}3:,04 *&.J;m$Eq}_fbT5ɟPU2=NaUB_U ]X> {n$WӤxM<.T0vO58 <ͧ~M,MI>3ƝK(J2X0.۔o,eLèNmhx=U^ cK`m5K(8Me#{Eݿ>ź- Z k25ClOJ1%;cfnǰ]"kxY/TZ$D)w"\sD/t %]%1lyqŦtxpPjY7' yB\)5&^7vNOhxQ~3CР3p| 7fwTퟖb>A]>8Of"T&t\2MDq歞^Y4i3L %ߝubJ56&h.Vguƥ Y4!uiwD?=5ȏ _tV y`%ʬQ/Zdy!-4Dg4.^06HkG>$L1aW)J) ɧKUp:6 nc{Ub6)eF ,ioD3ѣ"V_@f-7}qr9$inGKU`Zss/Rc7՜tUcgO~k3X|Q<?(vGX2dRLB&?n8 & kcEUK7v$q A1jXW=`Vegay2nYX>>a>ovnX"汸Ğ>׽)K_/IitYI+XZyŴz0v9k/(耶+ج\Yp/<(K=ė.ƐrߢQveFϳC$HنԆf!if[ fTGq 8yNՇɯ榶8VbR%T)np 0G "BW@`m>6LX7I_rma/a 5K>]GF7<+?ID(trsv v<7 pxugHY@LnUi3r,YNmsY{ )]$$jжbhҼ,!>ؚЉꦦ@!#s2}-+6ӱBuoiq炫|W53U.U`h>tgpu/h\mUHȏ6 >(u.E^@B[YL:12L f+F΀7%mo}-g*jdp4so2>5gP"mbxN)xנې^̵?'SRǤ{eJs5 m)XSqnVp/`NہotYC ti@Fۼ1rf@jϷTFRo+nPhѓ W셬ƒMSYI=Sտh2g%*d!'Bme2j /&s2)ZG>|u ܕh_|txp\tOYם4LI+@;_uNJ*Ov9}H[/)% APheR!4'4ZO7-kb}4`:A#'9>(S p߂ީ (d4As *NluO5̔I1 ΚLmd "6q$WY,j41= lf<5"U og`8fװo͞6`33ZT 3,ԝ^S+Lu_)K M'Y/앨?B!s4tˁC}DThd5__p-󓇎;ӓsIr #.7ݷ4)9:RӚIፙ|HrBq0S 96Xdxѕe @z{a_JĒQA@,\#nd1i=-yݵTLdˉ?BmuV2#{-~ K- ŜU7 ߿u?Agi!)"[IXe'3OA궑;G]VI#Un(T6(B $bs]rh x7twERo,`tiyߋ dKImG%br_Ӱc'U.89.hI@L*x`8-=0$StBM+n*/6G*AqW xP'ބ@AS@&1tE5&p>ǿkeXjpIÝ9^OR.0x`zGb臽20^f(^NlAȠʦ6 F#9F-t"vLz1 [2}7k&7rbb(7O 9Okȯ\\FWyC&eHֶjN)T(KN vJfq%4;F bE_d>.+[VNj"J?,s9M8OB.vи96UJ7HD ^T'Mt%eeFy:Uu\ K I^Zm9ޭK/*imC WdxkE[=p1>t$-/D'lgw'JK?2jR<b!{[LR^j š ?`vvVb `eÁBQK=N ?l+$/aݣ0#ʶvYdA`[.>:W"i g=ΰhP %ZHȽVѹj2i\oL *{*~+:l^'ҝ߯ `a>E`N@5@gbdcxU&*EZ`HfX^ xӼ E'~J]qPyR,Lh~3c69@z#>+`?C7X@=:/JY+"_T}yb%EІC{P[zyzYƔVb [D(NM`|q}E5!qDB VJC<{?5RTWk ?2SRى wǗIOVT;AgWRyLC,ՃQeԃh؍ZGxi+ed^'.TZ;q%'v ٦rRx&L^IrJwve!|ϟun!p0-,תּ9 :/"5ݯsTZkBMޮ’y|癊r +4Y Td#.Uf1ʊ#YK+1qDhS3:`4S{Cyq$JY_ D%ħԆ|oyvٛX'sYܚB$oۋBCXh!*bcOxĢ-5ɐ{p7`% R:Rmî3kzU b;WR˝)@0h.B2vj@Og'+:QPKT?1M>`X4(:tCƴLmiNQ_ 3`k E6mW>ԝflFx88^|kO2UʥKaԨ{qX {Y'9_D!|IzFc;p>|]krrD>+YݯIfWNQ;Rz͟c3^Npۆ`he ;!AHCyꑚ||)Ĕ}m{P!y2a9:B0)Z"B} ŜΨʼnŅTI+Bs6/&;lI"n5M^J_ۨX;_%iG#& \YjbxGf_~Hu9xn[bOf#~5"w=2z`ʁ).ep)82^] N|ڰԖ s1toI56ȟUMRx_Azd*էȯcO+YD:y[6: PyY1It eKF=t^(oa!9%(=F%'>c6jNqYӫ w7RpAoI!ps -+yD\zDgʓK}b8'Tiڇș(gZH&%{ikϗQuUߝǾ9uGN,ڛ N(ncA,=^>TK=tzpckON-5%\X9x݇(kjYaCH6cˣ ^51}5GC6X7!zҴWKQ Z1wWx5G +e?NpyY=/hGTc9_4NX*k d_`|t渧te"߂WјW=x'fV˿JQa-{Zkjyg 93+(%`.و(?∊a]-G;C2~u^㹛^( q.'/rN `Ywe ڀꌷ+|MW+8%GH6JB2%! _K;ݳNƵ (=W=%hS*$oeIQᘄ{VO]&!y45\@*r'%|$ʴM{+] N%0G\Yʂtk%04,h͏攞6S;GMaȔH_d2!De%(0 PXc ru{G1'_`̠Se#+ΣN9w %v"EUsj(u'F՝Hͬ8Ƒ[~o3ȺuTj5n6*\ĎWDj~6 #z<6׀<3,z gfw M})$c#U>fe1( G{YPPq TKzzi('˾Z582ɹBj֧y6PJb봴8r+LO4F,h{m,[3OS7^M*KlS3% THbf& cW~"#rcr#k<_ӐGtH nٟ l8{o}mi!Q.KERzX)g#1#l(H#p0ͨIEs#&sPD~nAUS?J1%Td~cn᫗^Է ۹ot9$Le)ޯ:*HB"-G a"ݟgf~*="0> :0FϳJ^.Ǭ^M}+$JW.\ uZNkĚءTkn0C'@6r28Vv("R]G aPD(Cv(o>K +#kI-hbhUWI(rc׊g9}U@\ZO0{~ +-(g h^t":6Ϳ7MIG] (f KWV6pNkn%bQt9k4oƭN ?FaGbX>4}Nm4Kgx/d.T~&.!vb`lWX]q &Ò,a0yz#$+K]pBvf^PU+ ͣˉ$'#9?6diE` uH~~8 =!,Y в_+DT!Z%z [X2@xWPZ]PPcd ¦jvx<\d!J*inVEt{N )U3-C|31W8`tÿy!G@{9K}rJNIX0=^(|~B~M{c"%&%rbޜpD엎HNT2׭ju9 %x /19yD$ab."RE $bӄj.蓒=-1Ȁ_DSUVb߹o:O7:wq] (X\VѤxSa >mVPW!њ_tqKMZj e29y7,e`PMR.ᛍIc&(0JD^KNwrT:6;>K;豲-c@e7pam#{q+KwSj 2O+4:Q=#C?7qqs&ZB!!]WmaUKFg tPOKugt p@FVZ<ͯ@[2gCFӾeb1YhvO _o'v4ktb/RgEJ g,J%B*Tz%( | T&)NCσWfLgZu%!k*y-k}QZA7x3=πoŢ2) =n۾x0o$yQE3yﰠ!ӭTtͮ'.dL-X>Sx5`f-E}hbALŐо_'& 61L#Vx-{ bP~Lth ]/l#[-')2&_D)#GF37 JIUًWԭ.Z<o[KDxQ0w8-ƃRϚ`ḏ֦ۯ̳FhT_ Rtc[yǃԢ"`$.w=ZŹX$r<,&U2yh3A0 *LJ=4pf&7ƾrZکo\72PWy,ERJ fyf۷ v\n|6{4KV ]6\w?>"ط[>_TR/|:?0Np]Q(nagI${1Խ f[\ $Xa>)?N_ZG%v?N}㷖wW#| Iq DzHkfAvArYk/P jogRpv񡣉b2t6's9#)s;N!ڟ c7Ӄp!/;N4uٽ WE؉pY+k xUp']-JV1=;8ia>lOVJ'@x5ݔr5Ұ|'S9ɐ/qthb4i2֥,HIzVѻ^M\FJ\Y<@gr_P6V VT1t ^. qoy?DոK j +\vlPc'wJ^ mҎ, /t% \ #b3dlN|RT`lu[՝LIrf^:+օNQ LXJRe[1uF8PE "PkCۆ~Cn~72/)<?=EOp#h3ץxh[M0DJkFS>[(; @a5!pG;bKniwKFڽ++`t9?\[މJ iRCr}&7^t,= /Ny(逡jI'%r%ULfjDfm\Ѣ\ xLlFJ1w_8`|~%(j%|_4:&ęZR6H $kɻ$QAFRuލ~jU>3s='3WQHDt&|pxb2-@߇[1 0iֱ)G0DeyZEooAΙ62KЛ-?5@~.[EfL_PMV"4#`jtBCRPsy埢Wtb ҎɦYceS,<"C-kwª֦rG4 pG2%`!r'k>ֶʥ # QҎVKtm):uThVray}44bN߀Kh:kX?6|:M ?SD<+=A5\Eٹ-Wh`y_dfLr{PCܺh4@6$ CYn$xѓ%,:<` ʯE;awj#|;(W؍I}?Ki?;Z>a} Ʃ?;!|B2`۸5楀y CyB5k6 Cۏ-HDZTr5Us.m.-'#p%,K v\t/!lp3E 8:yqK z,Up2+| iۏ,I4C^ɟ+=LaB W@:( E#Z⬄| Y|2iۏ+ށi[4swnmr agA2AKrB?isr E jr2p/g*R|JShd?TVvJ:nF'F=7;5Lh9lo3|Y͝ܖg_PXm"(6]XB6s0$f 8t9-6# ˸ ñ6t \6)[d_آYᏇff`^0sR3oy}rƝ߽In]G-F1юpk1m n8)RNEn@IYYO4vٻm=g0u$ѠÒi-Ǫ1<K[)Tmm`y`[|d!o-F8< ŧ׭ dv=G!D<^*g / Q56\_xi:+atdP]&w4N<{RX=2 y7Uyeu:F$XX%%v1hFlÇ 4nPp tx+CdT0d/&1"h,|tLDiv*w 6kJd^Ala9e6A16 LN-@3̂O%.TY& ~,=-TsZ\V (yͽҏ;K&zbu}a_>Rb9FSSaP fi9:(誔8%ܚ7MԿfً151^ #63-WrKX>Z< 2,q?h'9F\OEH LJ 1Ϧw붐"itn&Utϐmiѳ'&㉪C4)^w(d:#af]L]9,K;MfџCP(|&27Rx~A2ʈ o{<`M|!  "TNleF^!\F?| jyԽ@b[*~Zh [Ə^\j.u(cُ\#B-t+׾Qz*.k7chX5>n8QU|5HW$oYrm&}ܬ($mcGh6?hL M+#jԼɢ1(9$B&CH,}b4y6/RUqKEPESg\/ 17@ EԈLEW&Ɗ߁ctCVR=G$N0b*N\Ȥh,VKJ k& *LGJ6؛k>qWR ;ô'lSApၽ?g*;e(%DzWTE]ʱHRR2U4a?Ma)zBmk ӃhQ=kף >mKn2zٛWP* 0 E-.Jk\<^rG͏m}PE|wA7xlJ;V4̢᛼4QJڋgH}ߑKKk^l&/Y;pjcL_{w T+CS'n,ejj[}" 2AH.?VX`HŖB(Z^oYW۸`Ph|7y`ixtgҊ6jN8,=/ jY;YYDd1Ȣ!=9v?^!vV=ص%CmlmiY>€ 0陵0a->;;~e|l[41W -cn[!C5lҞ>1X '3dKJiGgՊ߷`. 37({4 0鸄M:pW%!T;met4zUh@XJP9/uyAFpa_Cy 7wq^ᝋtS!KPAU`PwH cP20*券UqbO0 dv@zq ope , Ρx?4_4{eUִE `r]_8a?LRrbKcrbʨ1bnx |ܒ!J&Z:feT2g,i9G P/o!C;4 vhOLuN[&{R :.*z9CafU3'244!dr6.%R5L=?1t;EU5V-6nJ3>sJe[I  XoO%zB]sgFs=o>K l0'I5Q|Е倡cYk_ 4λfVʾg=aO]tXTtR+dKpg.uIqJ6BTu4Sʛ Dw&X,L/񄈲ǕoQ?W #?0}Y B_F-ahml =F:+I ?-Li4w#RU)3<+9~3 ;ʱpq vigXvu@|رÛc?t\B{z97FKn+Y#˲Oy'l8WΡPT#98t-dOG&Ys0HB:ּ䅠FUFp\Ch6KplnD½xj1ZfÙP:Er}=}cm? +g /®zBsne:ѼMUa?4l{U n]jrnĪv|4t2ZBB'&,7H8$@C &u"S.S[}' Iں([cSlj ˾hZiaN7"4G&1`*5cWw-pUT=ZK)(C"^L>֓1K~ bֺrBz)AuCN-Loն/ cI@~4%X2p +(7_:}1Q  M "1 "+,.Z%^\dX ^F0 gUiet~L)hK1;Xm8cn°Tφ] @ sc1vCT,l!vo@5I?] ')[Hԟ)=.?b?:/nHPQܢI{RfU}UDuIa-[wpw8x3Nua~G'?2 &ǖbOma9c n ҹs,Wc8 b&钽5<!1]Jټ=\ڋ]#Q3mA_ʬ@w^F>_ɇ{)^n⸌TN[vUekȽ1[03=S?:YT8'"reNߜD |%'/>ko]|foMiAgד'}_S❟O€< * ^el'!L/['X˭sU]9 n2z[k9ĉJcS:ϰ+ 4֞@]!Y%:jG*DedG_F(k |n!(E}%L*KYEC`N.ܽOJjQUbU]LPj3ڲ҉(JumKZ7|U>gEXB`^MUYsYoZmW`GM~S[vsߢG2F:M=~JHJW:z}lr&#T}7^a0Ϲg^գ8A onwQEE{S.'n\rD6KyMy]֨۠ 筇a+>h㭏vگPTǮ[&(9Lv$>84c&xnx b) -U9_NܼO1(8A˝Sx аMXrۻ -9>L]x|˛Fp(Ȼ¥BFL> @Ce:ONu9aq/o&9+_jzg0(5QQ+bjee G/Q Xȫub\Ā #R*ruszs;N>$Yi>fOG9G%>Con~.:~wiM.YC+󻉦I VUհ]?N>IqK.-^0?&a+ -5Y`?EzD#B"z0\2T@|@'}ɀUj`gs vq|U&OHC=EN*PMp Pa88ZT2 yc;:W)@-V5c5UjN1PpgbbC\ξ!EV ]!'^,P"ޘEz}0sv{0S+T~$ 4QbCHQ`"EOfYP6T5]cL8IIeA KE[dy(jSnćȶnRC8E_B~L>冻g7KK3]*|_h-pa7qBa%zC-MW5dfݍAkH|m@i Hn_'W>BŽ"U ?iOV?@}g=ُ<&wDbk>/*džP\; u:9~}q0r=22[A f; ҋGZ}8RYd"alJ)VXj=)3 UIi.akr柦bTF714iF1PypeJen4A0CF5!$jCx.OS=(?5Wp4̭C( kut.l"FI$(rnǴzSĽ{7c,*E|w)03lČwCq'ui͙ @W)ˣs^DRBBl(Pra<;pSD6쏡gPeF'J}^+^ΚdW~Hd_j9o[K"zT❊~؂Nt4 m;h\5dZeߊ$kQNǒh圇7]mTv@\} @?R`eyPaT ?}*(BHNd I5ɥ'uT+WXM:ߛ`bk,3,l \gԎ,v@w1 ɚF Kdˆ]ȩf*o+3<|@=<Zƨ)޴XQ(Bjp.<[:IDGlFEu:O|vg!KD]Ž $3ҦPa\P)VR*{Tolʚ= D gH.-^T=OM(wAx 4p-3%1Yļۛ&Z}9v9c;RA1cqB{ N'T{GxZA(ң*$ [0ӥYA,b>B$y\+wFu=f5LSfnR ge(){@7Eb,_yDm=j<*9Iwĸ0iG=~i7mffD-r'̡Қ0dFJ{OӜG߹8Z>jT8 J zj,Dq`>2MCe۶= t]7-@}7Ia{ۅ 5Jfu#Xt{F6)Џ\go '4WΈAgۛREJة1y<^hcФL З #Gc o}aZCpB\jg}U:t{콰P(U#I4?;^k9lPm@D\Œ>[gAa>AOmv:o.cn, k`c73CQ kΡKUܫJ,b0MwWΗjbNVU9 E$/!VQƜ73<*X&l+eYzߦU{S! O[S 2sɑPB=m(f]':@%5gݭ1JFo"l UV ^TMr;˛ldF{hҗjȽZ5F\U/FM1Ԡ%8Go(vddAYn(q/{jH?720uHK*v>;ȮL3Z]X$؁4c40a%ކb5,>yYz4 !R)KPObԵj RR'{ S'N;3ЯW<٧-Annk܁}8z:c˷7x&&eHM㕁:KDƲ1bjDijI٦TpEG=q=19o]; g9HåcVH|-9jߝU+0=vཝ<1:jgo-u瑲_u2p!v9?=}qlAbL26p4bR|u-#W'am5E7} 0U:ҟ;Nӛ A]!~S=%F-QE r7v>Tt/!|6! ƥtl40=.e"ݹol.l!]8)ta*u?UW}iINJS4J" %;EEݹqGx_cu f]`q4T/As\7]/XK<7nрk.dB[B1zU7@7T@BEa-xŘlC/ 㜤Fn)n, 'ҷ3zDg!E)?KeIY6D: D}ͪfe&l$= ,R v7~T6?O$#sI <-8 F҅'cl[šrmm>fx<9egqJO3X{E ȁHOtTUp_"NvᓈJe%+ާE] /[u߆X~=Qء,v*Q`(Ɂ73oX4tj~McjV2uR[ xǢ_8Wu/`[!@d pΞ,rgZN=cAxV\~,8;Q#nӡbqu+H;EuS8K M1{ZPNNM$ QKB7g&?|n W:9E2:9\CF{V jSsO`(#4#?]Aǫ3S"lzSn8Cu5{6ӞOvoD> s=;ӥ#?! [ 7f׾gvmfw(㞽xVh `< A NG϶Cb~T7_}!0 ڮ !YitsuMu*V~.b9!:)p·*r_ t}puV?}'4/f%?s:7q-S[7\nox{a;|Ipc˖i4>ggy}*jrO9Wu~6Ź5KZ_hGV'Ƶ3 xEYxxz;iñ&@r)vH,UnoNEAҥr)( ٟXcr:ir(#yqmVRcǭKU,&DhNrlpC ݝ.=kPNI^F4PJ /_[ /ZjLN\ >7}HQ]H 4NI==kVfʗJ] ʼn͂#o5bJf̔(TRg`k˔>e!hYVˆ:xlѧ:Նs1߉lȦ:z|ĪfX5j]'.RʪePIE] K<)#:jR\w)].kA /z 8SgB!pڛe^K71^ Gm-g#bRyޡ/)OuTߜp5zR ^&2nt:_dZGƢ|Hܦ)eR=e?ǫ?WC0mx6\lQ7dgpʽ)K`@T]&=B튌f FZA5΃DM s(T$36Ě^k,goԯZD![}E%]$P"xc[f6oȑVZ2,zо6a51AI5yFǐ2wWjF0ys݃#ϬЪt ]{5=S^p{?b]M+$hU?ۥFuo8%1` 8+R)o  ⧖/"셦g7{T4v`㟏}@_gr$ i86[ru:颰q[6NwvTD nͮ. _OQQ~  eҊ&ߛNK`PV"UWk$ 4{VG?Kj !Ԍ(~s]T;5?;$7C@)d.!G}.sT8YaA_:VMzpV:&EZʕ&C"VnӲ ~gd&}<@ĭ[KR,:=NjƇ=FZO_.w\ Lm.`.l.x*y+̃d(<Z, Y)톽7\DLUkZu\ ʵJ߸;N)2m Գظ4C7D:~BeʣIp@; ?VɠlaVonr숯uI̯>s)F^0Q$>\1/Atk5`"k3 uڵǶÌ_J54B5hImjGe2w )V:6°4\ͨRSG hW.quzdkdA zK4*`1tD< >R~w.|z•'Tk2^] 'Lln`b9ֶ765{4z-EF-Yt3!u[b^y _aLk a1F峱>zƜy ja61"9u7Tf/ i5+5 /crku;>_{_QV~iLl }j72}|KGW r{SYO)!Y|GVƵ5\y[E;)%=͊-_RNjF0=wКw#QĤgqA:y?cj(KF|ߒW&t'1Q3$dLoK:kN6A}h͒oB0~މ7 N:-x Ǖ %f\[zE?CYv;;2*{>mCK.Ym;':Ձwa*)Ȇٻ͠mI߆ـ.u9kpQOWa֢ G'隯h|a[gN?biH_J r-ӥ ZЮ@t<̭exO LNLM2T'><>4w5PtpbKmfXPaDdhbK>M2 xC3?]j Mu)jcը3+fpX$YFW|EQ60_j矴ivw8H59̓ٮ8M߂ƨہXyJ~JkWfZYzCkɇTxDŴ6|On;npn]yK'k}H_UV#WޜXnaĞKpnmiZucWHe!uv}vf}#}E/߮p2Vxhc+[@{gHOc/$˜BѲZ|Y<ƴ]1*-<^^LbmהUEXQg?3М F~ʠNnsl&w%>z";T1)[l?,hx[$xM!/GtB <ZO*8Ӭۤ/K#PPW뗡LxLEzr y>n ѝOrAଝEQ Ps~h*̪( ("n|i~tqsFTX]tE8](eDN+e\Tx+43v6FOjoǙx -y a!0@XJ/xL(jE٩b-[K'JrZkds22/i4ф xlK\~$IўF U1wp^͸k&ۊ" FΞ: @* ZΑ Ǻ' CwC6ʟ7ҵ6*HWԡ V+78$/|ow fKD%h2OchvC.Zs tࠜe†jpe7GZDfǭhhd`o;ָJ/k%ϳNR0Ʌ;b?œQ@33ƪ"lq'dwy/1Q [C ><V)V^ȉbĔjX5jFyG1y=p%UMyb{Qk&|SE#IPK  *q/_}ors )?)H+cfyWJo5 =԰ H cdbpȦ4F8 BD."8ץKBz$~:xkMVm#]O".=N x)Ӡlt; + ;{yq)@ c8zӓ9Aԙ@*ݯ C+pL̷О$%fu]Zo-ajK+nP\h]4|V\[y/V<ޯe,_᪑s*di=Ƥa..ue+bPR'OXDA!O4O% 7E}zS9Ox9?}gM8РFڗj͟drru+L r %4֛?CMbAr\}4Lu0_*J^]braO4[+Q\ݧlmd7 Q]һTjK6y'Qd,7}惈N9 3> ª_o0;1#IyCbi?暴`X\ z\<(@rc{_la ~>jB qN:?e=lV0;]vBxq+׭`GyW{/Y7nŋ!/9UG 6jw$l, ~2r=uq%zJ ߄״q]WثQp~q(Kհpt-B(~A%%s,$7EIDLU=k'Yu9ל( - JFWk'{0Cb- G.|hO Rvץzzmr!*,~Rz⴨R C /߆A>MV[N.$2=؝^8jœmfY&Q/HnLn0Үp֧)G܃eK 3o&eNfx;Wcię@S,C+^6piq|JBdzݞ/ cs~,2(oiJy4 B W-q,z~f+Hk0vOCA=PLJ#Ġ/V!E90_L;~S뾙Җ.,v;F$urkկ%`(Pu`bu{CҢ53bd""GgA7l8J/h)C/Lϔw ZL8Hpt.k`NՑ53x>`Hke{}٦MG3S TPBr5i [!+6O#$p˂- [M?@ħMG29$+vi `6B +ȄNO>=E,nm&2<]-y23ʸahf0QgI6Bv^#2',t8`OC9s?K W4x}ի?3?bl26eb &gP6?̒ѣ׵+Bxu",?*}Mp&u|cn&s^@yx/+ȣUsVXbGitmr׃R29y4UU !ȬYDE=`HWk@4 !VN]x$%\E ϥG=4[2) cMq6o@ z_ҒRtM1St( wl<7>~5٫s'1:F#TL#B̥\$# ~ CNJGj)o:e-2vQA޲Y{q=ǮMŦD bO6TpnDHsTTƪOT}FVuU${0JsORn9˜H5A9՘7b!W6\Q .6eK_4 a;/d-*E)zYhD8#*S0,QdҺ)GuQTSxnC p pr:ڴW٤ UP|'ק_&zIz\ m#G3|Yt ;щQ+`WtOS!^1Y5{oPi9)8 0X`b`]_p5Hg1+ ;iKW!o8kf _T|@a{zяkU:1v;vO6-%7MdP[׹!&Mt.|{Ծt5Z$' @I"=  J0*>@ 3̣Q}]JVTYYAPNeO'v FA)3=չhj7k:pчI st]m.[#:czL8hOaͻiT x42w! vxYhZ# rN]cb 2U1mu*"%p:POK> [dKq󋡗+JXZޚNJƆTт:huBIUP!bͱ7l! pl(aUK&Lӥp{=ӑrk PLyѹ t +܏q<<#]MH3h0qVѲ\'l;`'HԘ1^닒Pt͓S\Y 7:zY#^h'e0cmU7,8s6QQ U ͗$*5o )I ސk`Ei{Yc/j::N2r&ZEtHHr Ux"BJKЖ6]8Pňw:B5a'"0^ .AU dDM R77[;Oq/b|N@ByԀ_l='1ߦ51/MW]8A X<W? aeV%r>InJ$9L!=p\6qʤTۇUv^6Mџ0b'}G f={$ H<֟<] )fN%OSiըrHegd>Q`P NqZ k' R{օFiN[}:ZËK)%1H,bUts=+>Q,S#JpHIJS\V*Ն=w7f@BUfh I] L ,)Jx|mvZ#S8ؐ'Fv?<z얤}+9]~.(ZZ=QЋu sgFk!]LRлձW.Rا7s}RS9QڞsmHI,5ߤى!w K7V:?m'9K텔"\ y `k 5V?pv[K4TK:e;aSE7p5[Y3 y o)^c4q워Ʌ(Kfϓ6]]DSۄaFلv-ξ,݅7 %% "oZU4CDy`vY_hk<rn @SWHڱd0ڢC~ -S6K!u7<devH=oH B~C-OV?jcY EKa>2hw"?K4,8$yKy~WPU :ExeBkd2iM|3aQop1kOdVP9?\5{wmP4kK#<]CyΦ\d-#q8 _BJ䣀":ADJLT$ZQ*+uEܦFvk:ntߒK /nU(m 1O}:nfCGεx54 B*ٽA\T[Mj/ɜ@'hKIru`~?yFc+CghYݴ |` ҉sݵsÞwwy/4o66:{UZ{g=K~hl/=ux3~)a0MoCٺ,[ usע9۳ѽx'.5SF ?}ql}ɬߞCݓcci? G1J<]ꖎJMY}fY&8;?_D ZQNQqSGhr䨙Eg_DN'=KY>:%Kuuy{zR9^[\cԖy+VKHL -yHZk'x׿ދru vik~{Z/*u> mDʉc- Ln8pBS1Rh4P] LS!b<ȉi Qc~IcbwZ#6 dL,un/5hk)9brG:G4;M NK"; 8BBLZ{GZhG8c) ;3`WK*BQk-ݯ[َ'KKr-n2p+sɰb1F]6W@-!0 ]AU~v{X4^0w9DgA5"n\$@JK_| cIME< +5+}$NI\U:v83ǯ霴kF+L~. Q YOr x4^[Sd`i+}H+|۱=PmSׇ<1AQ>6 ^(TKL_@!IS^N.r-}]X`sen} 8o?P0,*GCOhX XGeEqvՕ4M+h[Y{(^GX!ÛhPWX{h6x} `fRyI-H|1~\YU^vRa(U 83~o+ϭsxֱn4O`O,eb35vhv9xF^x-jrHٽŒ %9}DCokݧ0:d3@"ђ{z 3pۼ(tM߷Ewx!1T+?ն@ag+{N }e(RN?ܱ:_n lUg }Yt>f!@}6\܊mu;-3E $%Ҋ̫tXݩz,J "ovL()WPTץy G߲n*^>t"Ưp/w!}Qrđ\ ;Zt)U ڑUιN|LfXZ;"݇rL=h 72㇛[z *.gg4M4I5:6; TX8LQ]WX8P+(*"'5}Qs3IG%@5B@KY`EWg4c5Sy&k0(䪥+.^LcKȑBy B"^RQ@`( |VBmŒŠ1 n&z,f+7\tΩ_Q&ccvH*wF}& ht%bS%_ q0߂c)׫"6$cog=S: SVʶ7KRxdlgyPS5DrMR4,]889I_W|YJ(dwܞpuY\bMLV &n}l;^Īc@@ .26 CBQDLk'tQPkysJ&ƔH8<;#&v]i/Z6<d/tU1W+WM]S%ކ:{Xe]ȑ] r$s4,J&+JCᜤ``Mb2%I@ ھw+CL4+Gjs2hT͵tMt`SU5Hch;*n뛯c S8dOjVįNs/F R]v"/1Dy#hRr\n/7/۲͡mEk&S%+s8Qh ~AgDTfSC[4\&'h+]Djz Dp>1)>wY:cȜpbL*͖C QNfTϣӄq ,_N>4biIS) 7 ۠(GcN lS]JY_xd޿M ́@.uM:j@J~2M%` * oӺc`v ~(e'x\Q[9W sH:C#ɇ*@g7odkS~bmum1"3DunXOYe0N:'ղ18Vk߁KM=W/PpqpWd~1jFt9l$0<6y7d q<G j}J"I˝hY5)^A @0 ԑW}.O\ /]ZL65Sb!;qG^S乡BQ}p-Чلt&T]&2ׁ2\nnͮisisLw(͋#CE(8}= BX=ʾڡ0¾f:&?m6.KyC7&sBOKgfF} cX{h̸[ꐫ/puCQ¤ wQ, WέlӜ ԏiGa 7Mo"AN$lql~,~o=9qgXM882_]J-Jj ,L{ˣ*u8[Jvqod)/QT퍩ؚ|Xxa~:fg: W }0v1F73'k&K!>`'xH:"h5q]b/V>}G~\cg&8y6_=PyӴ..!5h}=Fecy\Tu 6.&TC#ۋ“lxgl_QͿPt=>^' *>%֝o1=:z'S`>9. /Z P[F_' y]Ǵ~ʲ6y3MWl|>9i& U,kڰ,j"lnp?&~]\>\ԾefP7rqCc@6wIYl`sZ3="~ TRi^KGF~ZvQH 6KVSеL@j+[`;jbԢZV KzB|ty7(*=.&$S+m,X-e'6h<,S~:Sͪ/kk T(ppwgva~Hb&IvjC(,Mtȓ1,Y8ݡ#۸2 {Wm-.|+FB0z+,fB1$P /WFck@E2a`laRZdyٻK3DٔX#c/HUP:pg;Lȝ%(`,ǟD$7`Ef}R2t<bFz8fF#o#ߺse#Ϗ!W~_x$Aә 'i@W^j$3w;q39 K3JI/&+ ?xLes7f o5f}7N2^u~:2̪j7҇Im^h>pU/ly؀t KѲ{3lÑkX+eYfdא=sz.,( FHk}MJsJu9fF j&]CJW}^9 Q'] J{`y UW y ^I)&WnT~60%&-hdԉ^ cn vfvp)Ҩ#ͰdUJlm׈a >J+c g@Xњ1Aq@)+?`eRaT͐EA\J46S6Kq\)YGhb( 6;Rxs-O7X}oHqHTzFvVvq* 3[peyKWcyn❷eQ, DQy g.FAMow\bS#_:N.vTGك ~; 8tЧ1!Z'޵:پV0?vtx,t1j{|̓ ,Y?dҰ0ƅUB~f0zRUzoy'Br.g(r СkM8+VŪM-$/ׯ7\Ayur'sC@70#᜜K8#0#ٵqL\1G˼Ԝ$M:x;.s|sWb1C^= u6-`*RX)4ؼ^ԎFO I1CZoTg^3E5ܬ7!m6ш r| \oeƯШ͙R}]O 咛d;( O9rlA S {|ÐD8K]t?*ڦJkIBq}4oA].41sEv b~ n^z$-x.,Nu08+}R?ne{a4!\a%mnZ'F:_xW !ɢe Q"NKzfFi7G-Sr C2btǸn[9zw܃N.֟qH+SKֆ[q-ghYegFS9ؐߴVy(YZxUMۛihO}^xCpYڤBP:0̵>'MTiօz]\qhf2cl՚G{Azɧ0ʔ.BnᣅxhV|Zo+v鰶7ALHJ}h˲}*GKiM&bNwD/CZ4XPzK6\1)MT[Km"ՊՓgi|-U>x^GZ";?ᦒ0CD0e}d;]"7׋m] FvjW It˟ݔ8Itj܈1> YjX,;2:#ec9+{+ش jRm!-0/.,7^.f6eE/b"( ?*Y㱃gsJb({Gf ]}*d0Z$È֧T0ӐZ^^W8vYH)dXQ3{V}vdaG[DrHzG1uwb^.u/вI D.yPI!,V>̭[Lma'2l=lRm9Lm$mϻ OB`~]wGFӕd~&(fqvfe*X{沶9#$P1{f>*/-RKR T` LE5cnq'i%{C=aoG3B ^Z+_7r~1mQTٛF%C*O{(9w*=?d8jiG+'2?K"1uM?V>IҼ"+,yg׃ ]'P:O C`S(]jPqw-=?v=qEf{D;Yj+|%+;[RJa'8 i2ۄ6 }UJ~<2?TgW1Hv@^+mzp& 擣L?xq²zi$Kɨ~Uy?7D9W^jb  Xت3l=1d[m|0c`o-ypTϛp̱:tm dqTǾ_alCj7^^jܪ*攇erV%\z 0fsB&\,w/֥Ş<,+FzZrm&z:t0Uׇ38Urf[Gt!ӎA_|ufFDȉlO.f|FlƂMϰ"QλWb k5\G2jrS5pb`PN||^yc[}ґp%d;HLk6 1J(~{ao얏".睏P^/Fzd-wba0zṲլ#atY~FvOe eQx\e Ŧ/7U̾`em?``hdJ5 +@8TȞus~Ta'z8?8F+XWYA-M1ZѓsL ^y_LlL>"| /RCɸzIs 3N9e]Hk$.C?Xp[uQマXRgt֞>u1#Mlq\$T[fn ڛQW- oKoVϿYJpDQl*FS 3p{X#Ʌ'Ր;H^ILr !:sj׽l XQs3RUX%=pq H/3SYsJfLs}رP;|S=3خBLưLIK߷f6Q5=6\k"-xF/3 tuh@Aް\x 9_GacֹB>{-zw2ATW/Y$r˸6J7]:v.k܃rLM z0ex}}zf9WY;,7.0: i\\mtƹpmozJf*l2VS6m%Cn;„Svݎھ3#(V~m`ttwՋXx"s`?u$VZ-}'4ƹ<pXfEW5Rd]> S뛯>:tx[=Mԥ9e ?~Z*hm9,\쪦ca͆j֕PBΧ}M"*'YW}Eanо 5PGʝw\vLPo'i%x'C4:k24,ԲQ z1 LՠMBQ93D+|9G&r4*tu?gG"ʙx]LT'0HQx7 MSZo=^9T̶{.h 0,oIRS5 bLO.yQDhJ|̡/bʮ{S-1 \d sPǓ{^˅}ǪaPpAVi /<[*;T{p 0N]Q0/2njgOCm|UM8vECq|VV47:PyV|@!dVs-a01t\6T*{_ XOַASh%q514VrA5qtfr(W" ̴쉐v=,?1)Qc`2LQMI]o%'@7:z,OPWv{4׆"nҊunT-+6k$7ebZ 'yNA: K\eg2)T6:$c3ܠcr,P=<i EwYn-N3+cQkg>տlÞUxJ5/'D; 0̘>O= ӁRbWsҶ-NHOBAI$F?t* j~I#:G'd+Hs?» <Rw(ty={j07Ӫȅ/=j $5vp)ރ4%_]E(۬:}{:\0wZ={ pGE,Sx^0eMyr cPKWjL\("Q,Qn{KS;3MNP ޹o kA bg||^<xRY R_ۤ|oA{N}W%>VʹT0pBXM<$9W٤:R˕/KOzH­YSmPV{0( vqHF#S^S]DYRGz }-#_M7@ Y] Ì*Wޯ;"a"WM ~i/nCIuN6ƒi2$y7W 7=f-G%ʆ49Ȣh[AC۷IDz-^huЋGs ye{ҡP}a];"% D>(|:\e+^<{ :x}I3 )(O0oQ)=D=eԄ' (_ɽc|X&n+ze@KtZKUG: y]ns䏮^4FHUH~C{]N%8vYe,,y}]D7#(:)0@6~w0NJ-%(ZPV{\uJ.s֡OB)l|(3{@W043t94ގۘ~w в V3$ L\ Y[7O ʀv&żάR>nuLpEnȞJQ 8z!OP H6rxT@6>D` Ac?cZi[[H3W#P+w߅Zo+J!= ]_Gۯ'M@3;GͶq̗$d*=َ̞9m@ν/0]}U'ߋ5yf > -O^'qSX'E>M~рY6ü.4L)o 2ܲGg7_hǞ׉胻Q!8ME3$W0J0'tg8(:†/wXwR@ގ91Kc`S&;x]~ɣ+[y.&¾࿁V.M //GaF,#נ9a.j/sk+>$[RW=a<2L+V,S@'KuP|88ѺQNj#3F-T=_(?,ٿW6P?_,D9k0El ZWpppssǧ0Ag,eqΩd< 1[yʕju؃W><l5S \?rށ\Xɱu1IxҶQyoF.R@izP<{2lTwC 83@hd7 ;_ GLcŢbk3-r8,!%h;6 Z .  /"yR te(+BXļX^x^߰밦L #RJla3y[=q/˵>gdHF/px}2 x=tk}ǧG}" &CVI[z3@*kqϐԺmOQ+͝K5F?FϘ8w='s@qK V/G6z@5>7"_guXI F6NˆIB+}&S7_+ c[0]7IxvG7Uk laTR8ӥ D |TM\ѭ{!sjK(|X5J k#uhܭ?68SQc*;9v\j3^Zb/PTٸƽ2:W׉YMF|; oM~ͽ+FZC"@"fO/;!V#E9˜1e'V|Tl6]&sg]At;v#ɚMze;a#u+Ep9v\hC6k5L" aLn_20ؼ'-\Ef3.0}Nl[z}v˙K(G5 8?BdЉБD~`e:"w _m+!{5~%!c8%>|*"~W2IG(55@7*DsdlrJ 6ZpE})C0pH sk]Lֶdd;<كgqY724:ja>8$|طg>Ѳ9UZ2-d(xVfĽ 2X0Dӫ#pB-AfԶs3X8no5ގ;IyS]PM:ZteN!#ۅ{>U͖)KK22 58/+ExR-5=5Ejk|1*jCZ?&6g%)G(!paQbJ|Q6`CpDE\֭t4D~^ԫreAd"|J` jAD\xQcpi|`u\ݙX3vw0ʋis:??AuQI.m@!nTgux]$?R!>Z1m!ށ(a\$>ǘ8"\rXsx&,:L*Vzr&ct6CE[ 2̈́(&;Z4!PJnjy~:@b-]CS<'P ]A,OSض֞Bradp4_F|a鞽x w%A8ѷ Y$h8Ys; 1O(@m-j Ii9il.cA=z~]SjvP\C2)8~zg(DZ1n'deY,-Zx?I-LsVFjW^!L=|{TrҶb²$WL$K(<0y,KWd«6Gw4ARe/ vWMaܭIQi^V𝨰v Y6\tSo,+ 9,ܱs!0#q^1ȐNQn捰mc.|_?B䯬 ʲPѬ;3pVoH7骋R̝[=Nad=a_bs?ۢhesۼX=(p#}5#dbut8xbj3ڇŇu- `tW"Fb: ^UV.qY*7$x &aC7 kNi9A0a BqvJޚ~HU|Zl8vbrۣ";>:/[8f:/m^-tmpKc 8$p a;Y4+ئqOqf¬/1dׁn[3&*wws.4z }IT4F!G4 'ݔRO]K`̼nbSRp9rY+a~%,zJ%a@pIu6 ~ַgzjSnin?zPnb!O׼Nb>˝,\>@z3V,Y'ˮ$TsBD)Qdq q$ 9**Sjw#%6  9 )@L% rzu@-TK9eD#Vþ<sA™1b3̸c6i; 6?0D/|(Uɾb5OodZYfec >2kr ؂)P!`5ZI9cU<09)Y) n FE %hVv{~>r`ChWM6R9JC?d b_sI]R d/~"'n"V̌:6o0Ɖ._Fť6<bvpاvpN{|yiy"#_*mMy]QWM%DJ³}6ݿQ X (>q=[r-N۱n4eP5VPAp0r\~5 kCٕk%'n4`ucOaQRgAp ΀Uy,Yr1+^ :x=`XŌ9TrAƴP2ޖ:cg4<~"Hm_r"d}&so5yֺ͢VMQzDk;4K^RP2~:G?qmcV4(mˋk'ڄC.x̟a45W h"i%lOcmsP?5TX_8D!uR»Ӕ~#_:58 ٵ] x*R&RJy ې:LB;G-\uEQ'h2iTJrC7@ݰۂ;:&>s  s s[m0\EM@V]%(rϢG^ IT&熖9}]Q28-m/?צ,ĆEY;?nIVzvPUr_Ũ鱴qrIޥ:|7d7 9N+z +ā}pOy_N }૽hg}]` V+qv8@i3eLǫ_ Dbf_ {ТiipND*OV.HRX ui>lsʇHzԇqHuߝ} hxZTT_u1дc3G%K]\z[BX(%q![a_1EA~xٳ=*IuQt[@\C6U` [-U^E{= jd~Pz:ҢKnMWMA?<AQ("^S?; -J2n갅>3p=f[/\j)Z6k$|MdBcQj vX+h(Sl]:Lj@1ǖBr 0yhBTguͦBΎImZ[EPԎ?W08)p.tßfX~ʭa5^W`5ZS8&]O|c,fv?%L!A]2C,NJ bs @_;G=hsC{!3C"ݜw[F(%U/lm#wv7>5 1W!  C5zp-7"ΞG'kiX yƾi($tq=);1xu4u ʓ ˜Gi'<5ܾY2%O>l ]i-&PkD>sN.\_;JgU 8Qz}MEkkwfq _&6yjv^&ݼϞxjM<Bۘ-L$Ǐ3^Pv\ p]oO܆{]rŭ_׮SͽYLҳ-k dOiw^\[>iŒW 5$p'TaL /ḯ,!qޜyq Po3 oUM+ ZꌿE6p&w H[I\4P].(a^ <ꐋpʞ .h!Tq#JtK/s-\Û5ŏ#oq-$6p;Z* haӳVs_)ۉA"sa%SLHr;*BFG!r$2H*Pm:oO > Lp7LFEIM;*r]&,~ );]#U6) $S&߈h!3أC&%-q%u][>wO)¯8[O(S1<uFB}7ݳQe^{(Mb+hیVpcOS$GC A?DX KFNU(o9i, Y4U%1S,-?4/gk IiÙ^s))0aBPR짅ߵ٘4&r1{Tɸ!4TɱbՍ l}!i u1|lXW61k|:q\9W;TnuMG ^G-s^x2FSjS 5 PJ))x My%e73BÌOȉ? y8,L+ >&^.o#ǵ~@8z?ܛ{h]P8E Q9QD !VK7ŊP!ZRǑ֝ /dh*.Q~(Qr> oK}(R Lhl0Rs9q`|%BR!"uHjPpU 'v  Ԧ/>,(d;L'ʅ`{lEt#3Yt٘CF,w)^kP~rG~2Ŕ_vͮ,yiȎpíK"W˸@sJ^ԾCߎ :ϰ%om9ɵ_es҅mreN?cAPLem K 4,T,-g}3"qͯ]͎3hEy Yuc,@oB|Nm5|H6L7;黴9R<keDT\(.AN!Jdd7WϠ[MZ/hlי).zh!=EKk̾rs"sUp᥸Eٖ촐Jŭ fĕg MNywAoWW jY.-lNaF+ K&*sZKd eEQhUƐ1D(\ܶ7Pv$Q܅;$UdS=QeŧO89PvRXq}a֏e3x/fJKXoúE ]> qDg.;n`YT"Cl.5kܷMk*IעUYvPєf:R aN*jf1K8ygN.6C'CUmi(,N˸y5lh(1-F]b8% .ŪBS;B)dz_&4:z *_@߹q֨7e5ae@X)A$S=u@= u"$H4K%`Q)(𝠴>@!eXL!9(G0mE%zc` (E[PCqu91+سJ&k0%:h*.1K_XThR3-!]zcVU!xqQ'\G)OR`8M6VE+4XyELkVᩎ L=aXe=)[YfO&lˬh[F^"VOiL\깜h(=۾F)&KIHzs۷gztjW<9Dc_σ`)V%|KYN HPW}/މd-.d =n咴+DK-SP*>`ăYOyʉrXqyN{ F= ֥҂#doԘi~ԭ/퉋N_QrtOe;A2 V "AZԊ}叨,ι/ .]new~+DŽ`e"WwNjcrb ,b4U$0N/Ɵi}&dgkUK-bb {tM<(lD]Y%v0ȚUe|*(䥐8Vhp"u VINJhA2sO-E:@뾀F<21ᚅ} ݜtx+H,:[ Su;[̤EW$H۵h6͓1<;@륧,blHZsG6B; ݚ垝u䞹8CqS|r[9UfeIi33Ro Msw" Hb'J>a dd:dOg>1P,{ڡD~鲋XX+`B8@i[/E}/J7_ߡ\m! 'Ч&1L))q+Ŏ$D27";ujTG5ߴ$cM*vZ"Wwڀ4v!& onzvQrRiѭs`±'Gjo)&y+1,&w𒨏`nS&f@!2Gx`d*#SOD 壇=E4[y.?' )7΍Xn4% 9QKJ&4]C~/aRslKS{O8P-F=x̵jwťTE "5AT%zdt+%Qzev @,ubYu*VڭreʍcNS=.'O :c܋ fv{3D%!Aϡ1mcȾ=6"i[Oz[7!5D ʆG| ٽQع=ls Cb,u\c,ѪJ?=&{5K@< \65}ϬL(kQ6?4~1pj0Kz}o>h2=nDm@Z]U`@?SrNY7-Я S`6@ZEWģ&geB\J=~4 Տi x5^>mw.^2ec BeC$I~5T ^sL>翨VQFW< 5Q}-gՠT%D)oǏ/nFrc1b +Wn&mkw%. |..LJC óKgZdA7I_bhRβgv<B'(+'."fS^s#7L)vl>T н2Z*Ez% gm<:uHj8-xaWdݫE"7Too6ܼxK;d[rB]D=jYpXϮ}>3>L̏_Es($mfbXZ!zrZq_Is8̐TIk"sK9$쇱YК\>D'6̊HrQǵ0w6*%yw/)31ao,gwKyl7q,h =cp^ELa'~yf6qfIKG^eΜܬ5Aːmk:Tp 6qdWV1ջ"to\h!cNlڷq n)&$8{jk !ڑg|@[SGGs>}F`qeUvfzLMk 3 #Wv޺dO0pQ=Lp7 әW7*[,2۸ X _> :'au򂩱IJixkYY`+ X2zZ`7q8 єg@7C #t. DL:3Z=?dV Ý ~>WeJhk1By o䰝ڹD bƮ1x:~pVX854 <ijүx."wTo{68*!i2hBU-܅Qv(co=K6<$zv`8fx͎A2V; I² ڒuH!X%]OA/X-)h 2*;n6;W!ڒaUcE*td?F&L'9dfn|IwBws QZlƉpdNJxڻN'Y:/ mnxC|X+bןΖ8w_ g u8{xK;4^x=zևv) ֓Q i̖߈{niwf}>˻MX Xi'Y( myz%~7&NDV\sBV F?a`M.0ht;}4G j#FHOVg]qHS2tggWOWM%׶= (3cb!lMa0Y|RJ]KWlͪ髄>ȸH@% lHr>S"V㧚e)r@IȓLl+s`v[hkt]ԝŝ=ϒ*Q\7@\UoJO-jd$AuiO`G;`DvF@TWg"H FEvS49yy)>93O7 vl_|Y'>N U#fo(bX7V6;&>iDʠh?e"Db}It*߲9MRA]h{8PgGcwP_dFGbfbzy|e^vY"V=u lLkpQ>~;Y>fy#QA~liCsؒmڪe\^4hKbmMf.mAJ0̾4f` I;wن#Pg7*/iE}ɐdMmr` PEmWۏɽJ^W6C@#;4у?,}n84lld/KJՉw^vB&H4l\ǝ. nd@:261tmWW6nX^}€4[ynt[9Hrm'?𾽦NU|5LdYE 79BBK jQB^(xo}7)@o$q܇ZXB}{61?)c{26_ɔ/?@f +bi.fI|d˩St4;}J4s_ȃ p?|`JE4Y- >_6 +bo1 sgށ+ d5ehn ;f؛ZH"?ikP/oOWEEΕC~I&u)I.5'B2<1O V Al7J2T)΅&XhVaBG/&/V/&>kCDԪ;E,꩝IN\OW 0/F46 jJ,jvSI38kXf>SjΏo$u(#ALly[?shEv{KXlHw廵g5hK<%:n~J$giN0ymأ<8`U,d8<k i sˏt,=QAC6OFj4˜#$/sQE YHDMi"EՉwНzG ˛J.id3JY!ZpSJ7oZԹ5Vq Kw09 2hG!=,En0f_DR?2w=Qnm/<@Hd:3T͐vMt~n0T(#çhjN> '9iFl#YZQ|&I´idKid6Raq I n H#*'3XZLI"huEvbCRFn+o~:=7EIOtG:\H?B\aUp'r?EJ+?''7T3M+b_ =&>,>'e x*(S} " z{V(=¸J!>iC}r-n>B4 ʣ'MJ>'~>AnD Л±=xRG,T UDK%%,`=4`vʤeUpQ N qΛW ҒdA3jmݩ˙؟gm/ hG qk ~E 5CI3߼mkUs"  zm3X윈ba>L3E" atNe)tpMè7H&{iD7H5˂? Q҃]݃?Kt@ы;"Vy>\E9sG|q0%{rJ%cp6Md}Cݞ mQEuF=K'oJ^bBYfDVee``0+FCݹ<gq*hu@s ծZü14 ! t?KM#V(U$З0~=,nQFAg&f0PtM~i {pB72m3P+:䳳?ݞVfsxpX;x#Gqتl_6aGVڃ<@lh?4] YYԊ|t 6"i/m*'͐]kD}CU(< 4,xG`;Ғқ9ϏxMi*\mL>Mxg.w7w]:!LuaI|MBJO9-<5=\>/SnkHE`+Di:7}9k%#Gu6YIzU)tƀE13]zňbvppyMACFz?,@gzwggڑ{࿂+?؂` |h5\>Ϟ17e1/ƾk dIXoԹJ,Ȍ:_t{(P7K0xz.!7ȣP8Xh7Y14|ʣw0C̹'Xsc (b:߸f}z57]fT@we!LXݔ{a x:uCq^vŊ"$5]?9{xZ>0X0V=E^A# ,k6?Y!!Y\z[ kO嘂5SO5kQ&]SuS~^LHp?aS$XGH6yrfk'.$dr;08U,\ׇ/UcZqcW杸i~<[FTqsS0 E !'C^qIO b7} R>RWo쯫VPM6xe#=sqlBy[KNExIZ>d۱VؒJ7\5% .c y ͯGǁryR'Ypub41Q&mPYb6H%%Y-۴T^|_izQ/[GŔ1c9MMOzST7dps'pO)x^xr;$#\n}UZXo{q ޘT! f\?ɞau6 3n0Xj0oqa^-t([u^)%'>-eȖ cX͍`A?|x#lTYA>Pr.D/܇c}F7[COe{E b=<^a|%_k=YG_ϰB'p3CHh~66iuKJ/,sR~5V{i & K'nH1sjfM}4Vdv 5J/[O_CqFU$f\ě4~ɄP3(1C(.k%0%c18!4{Ǟs 3,禣)L?g;Zl] C'RaV?m4F8kʏPL@+&~HT,饛]j{iοq~C0 c: ])X~9]il\ C'SaO_LXBZZ8'zH.6ѐ`%}3qc|Y!3}2gV2^}qcIo7*;*䡇ލƎ f]&h0[u$dFv9q Ei*DBbV׏Ov _o߄]/FD"^T[{5t޵vY&Wop.z[>D p"ы?ۣЦ V]Ok?q:EQ.fCTzC=qU3,@f*DRnn%$8H? VAACyTF;w6d)g/Lk}a̖?ieU_E_Vw>IFobdCn, .֩W}`[òF?[bjY 2KtTʛ.D`O"A/ [‘\FjW"V8"l|yu&bs$K}D{ &%9{'9݇bRbA F (2 kQFF%ꀆj-#QWiiy/H{XC7?XQL%%( d5b2,*#*m<|tZnq2.hܗYzcҡ$#sH_1DEW>rNr#LK%}ĢotPte[a$m&sWŔpUIUsiʘF-(Xf?i4or[)VZYP7n~hzU,$e PMnASͲwƵDڏUfލyfŸ_ ~)b:o -F6}dݨ}ԩY=CtH#]8I&Eo"+>b.CMFc'7Tka3T64q*+"[- S,+hQiTiZ с1c.sچc*;`כů!MGfV cҲW8h] rϯ$$&*s Sf4Q?p= aE6+\-lƊXaǖ'Ҿ܊t# ksƌwmtЏ# xǫ<Я}L<'dT̨UA?:f#MJ ^32G-+)Mۃ3+`Hh2e i s (m%vJ<0.m7C/Jx ѓ'}gcƃ:,$sH?|&E@/ ߔJ7q ä A9Z'-65JkܩTB(W~85 nX P7`"RhcGS"Ԩ5(Lǒj>[l _E"T=)Y 0 lzn+sTc?lV)%w=RCS Lg%qA!I=+[ySIj.Y>TW~tp!'\N\oi;_nRf|=:%q]Ar ^cJJI$~Z1XJ1zb,%&,->7WAr^:U#Õ00+n#A|mq /L2BA_ l]fj4ycī3m_B~Iq,7$p^tIn[#sxv~ kYM$a=@%Ӿ,s/O)QġXɃ`J/2< }޼7ila )#}٥^P2#j=SOk+6СT _LM42b!gMﲓdoh6l{VUb]DA` rs,7a= d)GxISaǴ6#,2Qh*0`k9DY'ƅ:2=eQx<ϐ,Zf9OiI*D*b +(Ԕ~$= L;MKVQ` :- 0FHu}7HaMR kZVi$fmr$b 5ќF!IpW.r# AM?#/8ܤ m%>>S*ɳ1llTjns#L wS]\2:A{v  !ME`D(εØghs l1h!/| hΉÿꛛO=T ?$f5d1?.@ԢI~ȶan!$!10|}W8N_RsfK$ -JGrB kC0$.Y;$NwE3K kurL=W.s/YNd79Ii4MKhWbGޞYARrF^:BvBYhADkɒkVLNV_@xXfEqdgϜlѹ/W9` !:/3ϼ!lיּxC8d4t~IԫXT`J129\Xag@HmK{|:cA] R[Qp 5s;p 'Xjk#5,6mw5pr)Waf4^˛2Pg30񂕻]"\l|`|r+nC\Jc+=".9`qάy-q7=I:kI#X>;J x8&H:z\k+8_mSpy!)1'u=;XAb˗MEp M&^`vOG 7?8XA/z+kO~nM>ʂ*M(K-O"]BK9C@[GC,hZų:LNk~.8 'mtnFozvvMm翱#12۹LMj VA%p|SWf_8 W H3$t~볈3W΍ Re3ҙ]n/NIH9 Lz"ާ ik0U"hX֒~jlJڱ(h!|h$WZ֞p MD Ix̞(y7?4e.8F&ҥo={H$auit )Xw,PF"2>/shf >%#48U'?ż;u]l-D7 yuxF^#8 ǭCޗFjk(ΰdz 0.V貞Z8,6: s2 z4`:@Mw ImcQZ[h!׵lN5SDnj@]R< '6*f5,ljGcmfj%6{=u #4tzv ]88}A){YN-ŠUmrD53z[ř&a Or,pKLNʔ`ޓ!?չ7HxA^CMUBqv_y֔w_ʨ?&đgညMIˁ-zg"|Y9¬h`粜i>'$Crrk_sLekL!`sɴiUWmszr:ǻ|9ʊ7 )P9yZhIh| './T }+LL@yG ޛJeg\x{}RgFwmf0{¹hǯ bgdV# ѾڅC2jA׶ae:vRAPWhXaMϨJ*XS?37ilWrįTV{!ޚcXhYթ$PG(R{MÅaH.?05;5Eht?9T>Yٴ≷i7K(u1m Gm<'\ѣ52ȓ;@X|m;嚆m26hD1bI~4lms%m\ _VGxE0:+>p=_ gH 9^_LM[Kiժ$J1g=|%o !@9Snwj ?zC?ցޔ|51 :=ׇm\Ýƹ0*qLH-3<M4r &஌bg:]$rO RnC͸5h.A[0.Ɗ1${0.HUny%`u9FP5svkp=8ިRKGoxȋtĿD& /0 o#.&WHoS%DM4=bq,/'ش罘! [| ]l 9P@f?V*=!YV֛5.U*]0?{\v@cW⊘izVKhK| ǝqmo!|iQGcN':OnĹjdOWŸ8aK\#2QݔSk@G ,>`3T@RPMXɂp twdT! cN/Ζz=.#~)Hw7gyfoI"?qg?J=:;T@0~`)>8k;: 'sG8G;TBGpt! $0L23|(O.7 ~JrT|C?T8ʇ.BebS/zULkWFtsT ATyڹJ/vwH^-}%93Ϩ@s'+PŒ; O:<ˬGysPV1;Ҍgk0bF>͊;rn,oCu&jY Ӕ0cB$$[gO 7E:1LWd{4Etf[N?9\uWg$`XC&.1q'I0_0"'>.Ay (o\V[i6v15|G6\8IW%iz%o\6+k {)]O OiPyiit42:?Ǯ@t I<$u\ .Σ0⊫~hLNElJ .cQ [--783%Q}ia,̗& ״ߔ%Hc*$Q鍝w FCzt = w O'?}rIV8׳/Fee<i:pU{+,[1,8A] ΦޒU} dee׿kdY~>+"9.<{s!? @NyΤ5 kW(wR제׷#Z8*:CADy?yMY\Ƽw2kI#,g*~|P"+kb Gl/LԖvCO&57B$M@]}u_y'e*618uY't%Q"A%(͔3whsnԢf.hj'.CΌMkYV 6Oݯ1/z;/A32x1""v;ėbL}(}CT  W2rdkǐat.2 mJ P΍NW/T(E%QokIV(ګV/L.cFUxu$Qn JѨ`-=]A2]M@ܨhؐވ̝V!ιq|O~;]Kח4&l:kgC;0DGI1s\a$^5)tţH Y A)@PT0+MpT&ŊAIEH_+K#ǟwoE^L'.'@@s0!9fpo"AnuΝokWS&$Gb~%9 XR CeZTw&۝vD(#0x0T?+8C^ZcOP2'X#z:凉%2`)6~ܜ#PiJ#d]\ 0 ;WWezm}H>!`F 0^W~Mĸ a 7Vrv: :]Kʻ-P4`gm '``@ᤪ^ԇldʯ 7.H4Q@@&b̰,zLZA9#c`e`~wY^#Ѥh?A-Q+N`w!dC0[MF&HM @7aK;3WqOjP_s:[8:y4O;w&QKe_.r)b V(ٔ<䍮T/<,](<6^%2v]wXjUAɡpd&bW` ap<[:dH/ r6#DZn ol  ̼#",Pgw瓨i 8I%ɖ=4iYg+gc%t45@S \ `*g d4mםgΙ߼O0Dg /GOlH?Kц}+,I$f` ?˵5mw#k{ZϬjAeyN)WIsXzW]d˙KcْSz|3hzGbIط9F Έf9K\"oaY黠F_"#/$ 'f 3' l.HFcj X3K{hίD*@4*<4W8"{R}V 9?#Ӻ;\Y@86PJŖ 9_}cdoJmZĿpǗȞgVmCp[XD㚪z ._hڏ;+sRKA2xHb %ұ<}:OFU^H'R-. =__7$WITm/6̤E^,3pVW<"5Z? Fbq yy;E^,-r64 xTbf)}Aǿ8Ӫ䃙a!ӗ Cn`2uh{4 jM,xTiB~lp`oQQd|,s2H;%R[&#ŭ"ZPxH({(okQMfOQᔧ+PKt/X0HڣdE@Yĥ?2+h{q_<-@gg ޡSqIKƱ$48Ќ0Oa0П|]oK&fvL'+ f ZP895Ɖ m  YZ